{"id":"CVE-2026-85349","title":"The FluentBoards  WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, including a Subscriber with no board access, to disclose the pr…","summary":"The FluentBoards  WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, including a Subscriber with no board access, to disclose the pr…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-200"],"product":"FluentBoards","affected":["FluentBoards < 2.0.15"],"published":"2026-09-16","updated":"2026-09-17","sourceUpdated":"2026-09-17T13:16:50.790","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85349","references":[{"url":"https://wpscan.com/vulnerability/6526a9ee-6320-472b-a179-dba009f6d76d/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-17T12:19:18.469951Z"},"epss":0.00282,"epssPercentile":0.20931,"ingestedAt":"2026-09-16T06:51:06.250Z","slug":"CVE-2026-85349","body":"## Overview\n\nThe FluentBoards  WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, including a Subscriber with no board access, to disclose the private board memberships of arbitrary users by referencing their user ID.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":205992,"id":"CVE-2026-85349","ts":1789651140245,"field":"cvss","old":null,"new":"4.3"},{"seq":205991,"id":"CVE-2026-85349","ts":1789651140245,"field":"severity","old":"none","new":"medium"}]}