Sceawere

Vulnerability Detail

CVE-2026-96821UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FluentBoards Subscriber Privilege Escalation

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
3h ago
Vendor
Mahmudul Hasan Arif
Product
FluentBoards
Attack Type
CWE-266 Incorrect Privilege Assignment
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Subscriber Privilege Escalation in FluentBoards <= 2.0.12 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-09-30T13:17:31.597Z",
  "pubdate": "2026-09-30T13:17:31.597Z",
  "executiveSummary": "FluentBoards versions 2.0.12 and below are susceptible to a critical privilege escalation vulnerability.\nThe vulnerability allows authenticated users with low-privileged accounts (Subscriber level) to perform unauthorized administrative actions.\nBy manipulating specific requests, an attacker can bypass access control checks intended to restrict functionality to authorized administrators.\nThe impact includes unauthorized modification of board configurations, task management, or data exfiltration depending on the exposed administrative endpoints.\nThis flaw represents a significant risk to the integrity and confidentiality of the WordPress environment utilizing the plugin.\nSuccessful exploitation does not require advanced technical sophistication, merely a valid, low-privileged user account on the affected system.",
  "technicalDetails": "The vulnerability originates from improper authorization checks within the FluentBoards plugin's request handling logic.\nThe core issue involves the plugin's failure to adequately validate the user's role or capabilities before executing administrative-level functions triggered via AJAX or REST API endpoints.\nIn versions 2.0.12 and lower, the administrative endpoints do not consistently enforce capability checks, such as 'manage_options' or other capability requirements required for plugin settings.\nAn attacker with a standard Subscriber account can target these endpoints by crafting specific HTTP POST or GET requests.\nWhen the server processes these requests, the plugin's backend logic assumes the requester has the necessary administrative privileges because it fails to perform a server-side capability verification.\nAttack flow: 1. The attacker logs in as a Subscriber. 2. The attacker identifies the target administrative action endpoint within the FluentBoards plugin. 3. The attacker crafts a request to this endpoint, ensuring the necessary parameters are included to mimic an authorized administrative action. 4. Due to the lack of access control validation, the server executes the action with the attacker's session context but with administrative authority.\nThis results in a direct privilege escalation, allowing the attacker to perform actions such as creating, deleting, or modifying boards and associated task metadata without the appropriate authorization.\nThe root cause is a failure in the 'Authorization' layer of the plugin, where trust is incorrectly placed in the input parameters rather than validating the authenticated user's permissions against the requested action.\nThe vulnerability is accessible over the network, contingent upon the attacker having an established, valid, low-privileged user session on the target site.\nPost-exploitation impact allows an attacker to manipulate the plugin's data store, potentially leading to unauthorized data disclosure, disruption of project management workflows, or further exploitation if other vulnerabilities exist within the administrative components of the plugin."
}
CVE-2026-96821: FluentBoards Subscriber Privilege Escalation (MEDIUM Severity, CVSS: 6.3) | Sceawere