SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14938

MEDIUM · CVSS 4.3 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

The FluentBoards plugin for WordPress prior to version 1.95.3 is vulnerable due to inadequate authorization checks during board import operations, allowing authenticated users with member access to one board to access and copy stages and tasks from any other board. This could lead to unauthorized data exposure, including sensitive information such as titles, descriptions, and file attachments. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.

CVE
CVE-2026-14938
Severity
MEDIUM
CVSS
4.3
EPSS
0.16%
WordPress

Original NVD Description

The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy and read the stages and tasks (including titles, descriptions and file attachments) of any other board on the site.