cvedb.io
CVE-2026-14938
UNKNOWN · CVSS n/a
EPSS exploitation probability: 0%
Published 2026-08-02T06:16:35.947 · Last modified 2026-08-02T06:16:35.947

Summary

The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy and read the stages and tasks (including titles, descriptions and file attachments) of any other board on the site.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.