CVE-2026-89328: CWE-284 Improper Access Control in FluentBoards
CVE-2026-89328 is an improper access control vulnerability in the FluentBoards WordPress plugin before version 2.0.15. The plugin fails to verify that a user has board-manager privileges before allowing certain board-management operations, instead only checking for board membership. This flaw permits any board member to perform actions reserved for managers, such as adding or removing members and making private boards public.
AI Analysis
Technical Summary
The FluentBoards WordPress plugin versions prior to 2.0.15 contain an access control weakness (CWE-284) where the plugin does not properly verify that a user holds board-manager privileges before executing several board-management functions. Instead, it only checks if the user is a member of the board. This allows any board member to perform manager-only actions, including modifying membership and changing board privacy settings.
Potential Impact
Any member of a board can escalate their privileges to perform manager-level actions, potentially compromising board membership integrity and privacy settings. This could lead to unauthorized disclosure of private board content or unauthorized changes to board membership.
Mitigation Recommendations
Upgrade FluentBoards to version 2.0.15 or later, where this access control issue has been fixed. No other mitigations are indicated.
CVE-2026-89328: CWE-284 Improper Access Control in FluentBoards
Description
CVE-2026-89328 is an improper access control vulnerability in the FluentBoards WordPress plugin before version 2.0.15. The plugin fails to verify that a user has board-manager privileges before allowing certain board-management operations, instead only checking for board membership. This flaw permits any board member to perform actions reserved for managers, such as adding or removing members and making private boards public.
Affected software
FluentBoards
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The FluentBoards WordPress plugin versions prior to 2.0.15 contain an access control weakness (CWE-284) where the plugin does not properly verify that a user holds board-manager privileges before executing several board-management functions. Instead, it only checks if the user is a member of the board. This allows any board member to perform manager-only actions, including modifying membership and changing board privacy settings.
Potential Impact
Any member of a board can escalate their privileges to perform manager-level actions, potentially compromising board membership integrity and privacy settings. This could lead to unauthorized disclosure of private board content or unauthorized changes to board membership.
Mitigation Recommendations
Upgrade FluentBoards to version 2.0.15 or later, where this access control issue has been fixed. No other mitigations are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-11T15:04:19.334Z
- State
- PUBLISHED
Threat ID: 6aaa32e555bf5e2cf517fb62
Added to database: 09/16/2026, 06:10:45 UTC
Last enriched: 09/16/2026, 06:17:07 UTC
Last updated: 09/16/2026, 06:26:15 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.