Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose the email addresses of a shared board's members, typically including administrators. | |
| Title | FluentBoards 1.95 - 2.0.15 - Unauthenticated Board Member Email Address Disclosure via Public Board Endpoints | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-23T10:53:12.498Z
Reserved: 2026-09-11T15:15:05.364Z
Link: CVE-2026-89331
Updated: 2026-09-23T10:34:03.522Z
Status : Received
Published: 2026-09-23T06:17:05.083
Modified: 2026-09-23T11:17:16.620
Link: CVE-2026-89331
No data.
OpenCVE Enrichment
Updated: 2026-09-23T15:15:05Z
-
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor