CVE Explorer
CVE-2026-14938
The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy and read the stages and tasks (including titles, descriptions and file attachments) of any other board on the site.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"FluentBoards","vendor":"Unknown","versions":[{"lessThan":"1.95.3","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:107338792cfcd6ae7da1169cb9e5f44d5dde4eaf3e083fd5e6d085a91ecdac90 · sha256:47b8cbd2b1b73d98… · /containers/cna/affected/0
CWE assertions
1 source assertion{"description":"CWE-639 Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:107338792cfcd6ae7da1169cb9e5f44d5dde4eaf3e083fd5e6d085a91ecdac90 · sha256:47b8cbd2b1b73d98… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/44d91e8d-ad2f-429c-a21e-364b1fc13fdc/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:107338792cfcd6ae7da1169cb9e5f44d5dde4eaf3e083fd5e6d085a91ecdac90 · sha256:47b8cbd2b1b73d98… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.