CVE-2026-89331 PUBLISHED

FluentBoards 1.95 - 2.0.15 - Unauthenticated Board Member Email Address Disclosure via Public Board Endpoints

Assigner: WPScan
Reserved: 11.09.2026 Published: 23.09.2026 Updated: 23.09.2026

The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose the email addresses of a shared board's members, typically including administrators.

Product Status

Vendor Unknown
Product FluentBoards
Versions Default: unaffected
  • affected from 1.95 to 2.1.0 (excl.)

Credits

  • vuxvinh finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE