What is CVE-2026-14938?
The FluentBoards WordPress plugin before version 1.95.3 fails to verify user authorization during board import operations, allowing any authenticated user with member access to one board to copy and read stages and tasks from unauthorized boards. Updating to version 1.95.3 or later is strongly recommended.
Azərbaycanca: FluentBoards WordPress plaqinində (1.95.3-dən əvvəlki versiyalarda) board idxalı zamanı istifadəçi icazələrinin düzgün yoxlanılmaması boşluğu aşkarlanıb. Bu, bir boardda üzv olan autentifikasiya olunmuş istənilən istifadəçiyə həmin boarda aid olmayan mərhələ və tapşırıqları kopyalayıb oxumağa imkan verir. Plaqini ən azı 1.95.3 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
Which versions of the FluentBoards plugin are vulnerable to the authorization bypass during board import?
CVE-2026-14938 affects versions of the FluentBoards plugin before 1.95.3. The recommended solution is to update to version 1.95.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.