PT-2026-93315 · WordPress · Fluentboards
CVSS v3.1
3.8
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FluentBoards WordPress plugin versions prior to 2.0.15
Description
Insufficient verification occurs when a board member submits a comment, as the plugin fails to confirm if the submitter is the actual user to whom the comment is attributed. This allows any board member to impersonate other users, including administrators, by posting comments that appear to be authored by them.
Recommendations
Update FluentBoards WordPress plugin to version 2.0.15 or later.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fluentboards