CVE-2026-85349: Unknown Fluentboards

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, including a Subscriber with no board access, to disclose the private board memberships of arbitrary users by referencing their user ID.

Affected products

  • Unknown Fluentboards: before 2.0.15 (fixed in 2.0.15)

Published 2026-09-16. Last modified 2026-09-17.