CVE-2026-89327

Summary

The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user the comment is attributed to, allowing any board member to post comments that appear to be authored by another user, including administrators.

Affected Software

VendorProductVersion RangeStatus
UnknownFluentBoards0 < 2.0.15affected

Weaknesses

  • CWE-290 Authentication Bypass by Spoofing

References