Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Diogo Pinto

#33704of 56,330
8Total CVSS
Vulnerabilities · 2
Low
1
Medium
1
PT-2026-67056
4.3
2026-08-02
WordPress · Fluentboards · CVE-2026-14938
**Name of the Vulnerable Software and Affected Versions** FluentBoards versions prior to 1.95.3 **Description** An Insecure Direct Object Reference (IDOR) exists where the plugin fails to verify if the items selected during a board import operation belong to a board the requesting user is authorized to access. This allows any authenticated user with member access to a single board to copy and read the stages and tasks of any other board on the site, including titles, descriptions, and file attachments. **Recommendations** Update FluentBoards to version 1.95.3 or later.
PT-2026-66709
3.7
2026-07-31
WordPress · Fluentcart · CVE-2026-14927
**Name of the Vulnerable Software and Affected Versions** FluentCart A New Era of eCommerce WordPress plugin versions prior to 1.5.3 **Description** Insufficient authorization and ownership checks occur when rendering customer order documents that use a sequential numeric identifier. This allows unauthenticated visitors to enumerate and disclose sensitive customer personal data, including names, email addresses, billing and shipping postal addresses, and order details. **Recommendations** Update the plugin to version 1.5.3 or later.