Junglewise Threat Intelligence

CVE-2026-89328: FluentBoards privilege escalation in board management

CVE-2026-89328 · Severity: low · CVSS 3.8 · Published 2026-09-16

Technologies: FluentBoards. Vendors: FluentBoards.

Executive brief

FluentBoards is a popular WordPress plugin for collaborative board management. A flaw in the plugin allows any member of a board to perform administrator-level actions—such as adding or removing members and making private boards public—without holding the required manager privileges. This could enable unauthorized users to compromise board membership and visibility.

Technical details

The vulnerability is a broken access control (CWE-284) in FluentBoards before version 2.0.15. The plugin fails to verify board-manager privileges before performing sensitive board-management operations, checking only board membership instead. An authenticated attacker who is a member of a target board can exploit this to perform manager-only actions, including adding/removing members and toggling public access on private boards. The vulnerability requires the attacker to be authenticated as a board member; no network-level exploit is possible. A fix is available in version 2.0.15 and later.

Affected products

  • FluentBoards FluentBoards before 2.0.15

Timeline

  • 2026-09-14: disclosed
  • 2026-09-15: patched: version 2.0.15

References

Related threats