CVE-2026-39789: WordPress Fluent Affiliate Pro plugin <= 1.6.4 - Broken Access Control vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.
Affected Software
1 affected component
wordpress/fluent-affiliate-pro<=1.6.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Fluent Affiliate Pro pluginto a version that resolves this vulnerability.Fixed in 1.6.5
Event History
Oct 6, 2026
CVE Published
via MITRE·05:14 AM
Data Sourced
via MITRE·05:14 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or existing privileges to exploit it.
2
Which plugin versions are affected?
Fluent Affiliate Pro versions 1.6.4 and earlier are identified as affected.
3
What is the likely security impact?
The supplied severity vector indicates a network-reachable issue with low attack complexity and no user interaction required. It has an integrity impact, while confidentiality and availability impacts are not indicated.