CVE-2026-78279: WordPress Fluent Support Pro plugin <= 2.3.1 - Cross Site Request Forgery (CSRF) vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.
Affected Software
1 affected component
WordPress Fluent Support Pro plugin<=2.3.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Fluent Support Pro Pluginto a version that resolves this vulnerability.Fixed in 2.3.2
Event History
Aug 24, 2026
CVE Published
via MITRE·11:39 AM
Data Sourced
via MITRE·11:39 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attack can be initiated over the network without attacker privileges, but it requires user interaction. This is consistent with a victim being induced to make a request while using the affected plugin.
2
What versions are identified as affected?
Fluent Support Pro versions 2.3.1 and earlier are identified as affected.
3
What is the likely impact if exploitation succeeds?
The reported severity vector indicates low impact to confidentiality and integrity, with no reported availability impact.