medium · CVSS v3 5.3 · EPSS 0.00199
CVE-2026-89331
The FluentBoards WordPress plugin (pre‑2.1.0) fails to restrict member data exposed by its public, token‑shared board feature, enabling unau
Overview
The FluentBoards WordPress plugin (pre‑2.1.0) fails to restrict member data exposed by its public, token‑shared board feature, enabling unauthenticated users to retrieve the email addresses of board members, often including administrators. This flaw allows attackers to harvest sensitive contact information without authentication. The vulnerability is a medium‑severity confidentiality breach.
Description
The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose the email addresses of a shared board's members, typically including administrators.
Impact
Confidentiality is compromised as attackers can obtain email addresses of board members, exposing them to phishing or spam. Administrators and other board participants are the primary victims, potentially leading to credential compromise or social engineering attacks.
Remediation
Upgrade the FluentBoards plugin to version 2.1.0 or later, which implements proper access controls for the token‑shared board feature. If an upgrade is not immediately possible, disable the token‑shared board functionality or restrict its usage to trusted users only. Additionally, review and enforce least‑privilege permissions on WordPress user roles.
Risk context
The CVE has a medium severity score (CVSS v3 5.3) and a very low EPSS (0.00199), indicating a moderate risk that is unlikely to be widely exploited. Defenders should still address the issue promptly to prevent potential data leakage.
Affected products
- FluentBoards 2.0.x
- WordPress
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- —
- EPSS
- 0.00199