CVE-2026-78274 CRITICAL

CVE-2026-78274: WordPress Fluent Boards Pro plugin <= 2.0.11 - Arbitrary File Upload vulnerability

Vendor Wp Manage Ninja
Product Fluent Boards Pro
Weakness CWE-434 · Unrestricted file upload
Published August 27, 2026
Last update August 27, 2026

CVSS base score

9.1/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.

Explanation of Vulnerability in Simple Terms

02Summary

Fluent Boards Pro versions up to 2.0.11 allow authenticated administrators to upload files without proper type validation. An attacker with admin privileges can upload executable files, potentially running their own code on the site. The vulnerability affects confidentiality, integrity, and availability of the entire WordPress installation.

What an attacker can do

03Attacker Capabilities

Upload and execute arbitrary files on the site, gaining full control of the WordPress installation.

Potential impact on your site

04Site Impact

A compromised admin account can lead to complete site takeover, data theft, and malware installation.

Conditions required to exploit

05Prerequisites

Attacker must have administrator-level access to the WordPress admin panel.

Key dates

06Disclosure timeline

August 27, 2026 CVE published
August 27, 2026 Record updated

Related vulnerabilities

08Related CVE