Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-89328

Опубликовано: 16 сент. 2026
Источник: nvd
CVSS3: 3.8
EPSS Низкий

Описание

The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. This allows any member of a board to carry out manager-only actions on it, including adding or removing members and enabling public access to a private board.

EPSS

Процентиль: 11%
0.00209
Низкий

3.8 Low

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 3.8
github
7 дней назад

The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. This allows any member of a board to carry out manager-only actions on it, including adding or removing members and enabling public access to a private board.

EPSS

Процентиль: 11%
0.00209
Низкий

3.8 Low

CVSS3

Дефекты

CWE-284