CVE-2026-78272: WordPress Fluent Support Pro plugin <= 2.3.1 - Broken Access Control vulnerability
Published Aug 24, 2026
·Updated
Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.
Affected Software
1 affected component
WordPress Fluent Support Pro plugin<=2.3.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Fluent Support Proto a version that resolves this vulnerability.Fixed in 2.3.2
Event History
Aug 24, 2026
CVE Published
via MITRE·11:39 AM
Data Sourced
via MITRE·11:39 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability requires an authenticated user with Subscriber-level access. It can be exploited remotely without user interaction.
2
What impact can successful exploitation have?
Successful exploitation can lead to limited unauthorized disclosure and modification of affected data. The available information does not indicate an availability impact.
3
Which versions are affected?
Fluent Support Pro versions up to and including 2.3.1 are affected.