{"id":"CVE-2026-14938","title":"The FluentBoards  WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a …","summary":"The FluentBoards  WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a …","severity":"none","published":"2026-08-02","updated":"2026-08-02","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14938","references":[{"url":"https://wpscan.com/vulnerability/44d91e8d-ad2f-429c-a21e-364b1fc13fdc/","label":"contact@wpscan.com"}],"tags":["nvd"],"ingestedAt":"2026-08-02T09:18:12.367Z","epss":0.00162,"epssPercentile":0.05799,"slug":"CVE-2026-14938","body":"## Overview\n\nThe FluentBoards  WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy and read the stages and tasks (including titles, descriptions and file attachments) of any other board on the site.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}