Description
The Alba Board plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to access arbitrary private alba_card post data, including title, description, assignee, due date, tags, and comments, that is intended to be restricted to Administrators and Editors. The handler is registered via the wp_ajax_nopriv_ hook and its nonce is exposed to all site visitors through wp_localize_script on pages containing the [alba_board] shortcode, making this exploitable by unauthenticated users who can access any such page.
Problem types
Product status
Any version
Timeline
| 2026-05-02: | Vendor Notified |
| 2026-06-05: | Disclosed |
Credits
Teerachai Somprasong
References
www.wordfence.com/...-2bb3-41d1-8638-b69ceaff0b4f?source=cve
plugins.trac.wordpress.org/...includes/ajax-card-details.php
plugins.trac.wordpress.org/...includes/ajax-card-details.php
plugins.trac.wordpress.org/...includes/ajax-card-details.php
plugins.trac.wordpress.org/...includes/ajax-card-details.php
plugins.trac.wordpress.org/...includes/ajax-card-details.php
plugins.trac.wordpress.org/...includes/ajax-card-details.php
plugins.trac.wordpress.org/...ba-board&sfp_email=&sfph_mail=