Junglewise Threat Intelligence

CVE-2026-89327: FluentBoards comment author spoofing via comment_by parameter

CVE-2026-89327 · Severity: low · CVSS 3.8 · Published 2026-09-16

Technologies: FluentBoards. Vendors: FluentBoards.

Executive brief

FluentBoards is a WordPress plugin for managing collaborative discussion boards. The plugin fails to verify that a board member submitting a comment is actually the user being credited as the comment author, allowing any board member to impersonate others—including administrators—when posting comments. This undermines content attribution and enables reputation damage or social engineering attacks.

Technical details

The vulnerability is a broken access control flaw (CWE-290) in the comment submission functionality. The plugin does not validate the 'comment_by' parameter, allowing an authenticated board member to forge the author field of comments they submit. Attack precondition is board member access; the attacker can then craft requests specifying any other user (including admins) as the comment author. The vulnerability affects versions before 2.0.15 and has been patched in 2.0.15.

Affected products

  • FluentBoards FluentBoards before 2.0.15

Timeline

  • 2026-09-14: disclosed
  • 2026-09-15: patched: Version 2.0.15 available

References

Related threats