CVE-2026-89328
Last modified
CVE-2026-89328 is a low-severity vulnerability rated 3.8/10 on the CVSS scale. The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. This allows any member of a board to carry out manager-only actions on it, including adding or removing members and enabling public access to a private board.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. This allows any member of a board to carry out manager-only actions on it, including adding or removing members and enabling public access to a private board.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | FluentBoards | < 2.0.15 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-89328?
How severe is CVE-2026-89328?
How do I fix CVE-2026-89328?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-89308An unauthenticated OS command injection vulnerability exists…9.3
- CVE-2026-8931A critical Remote Code Execution (RCE) vulnerability exists …9.4
- CVE-2026-8932libcurl would reuse a previously created connection even whe…7.5
- CVE-2026-89321Publishing limits the compressed size of a VSIX (ovsx.publis…4.3
- CVE-2026-89325An uncontrolled search path element in InsightVM assessment …7.8
- CVE-2026-89327The FluentBoards WordPress plugin before 2.0.15 does not ve…3.8
- CVE-2026-89329A flaw was found in `multipathd`. A local attacker with acce…6.2
- CVE-2026-8933A local privilege escalation vulnerability exists in snap-co…7.8
- CVE-2026-89330The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Revie…6.1
- CVE-2026-89331The FluentBoards WordPress plugin before 2.1.0 does not pro…5.3
- CVE-2026-89332Inclusion of functionality from an untrusted control sphere …5.5
- CVE-2026-89333The Tutor LMS – eLearning and online course solution plugin …6.5
Are you affected by CVE-2026-89328?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
