Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q8hc-f88v-p32p

Опубликовано: 16 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.8

Описание

The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. This allows any member of a board to carry out manager-only actions on it, including adding or removing members and enabling public access to a private board.

The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. This allows any member of a board to carry out manager-only actions on it, including adding or removing members and enabling public access to a private board.

EPSS

Процентиль: 11%
0.00209
Низкий

3.8 Low

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 3.8
nvd
7 дней назад

The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. This allows any member of a board to carry out manager-only actions on it, including adding or removing members and enabling public access to a private board.

EPSS

Процентиль: 11%
0.00209
Низкий

3.8 Low

CVSS3

Дефекты

CWE-284