CVE-2026-78296: WordPress FluentAuth plugin <= 2.1.2 - Email Verification Bypass vulnerability
Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing.
This issue affects FluentAuth: from n/a through 2.1.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress FluentAuth – The Ultimate Authorization & Security Plugin for WordPressto a version that resolves this vulnerability.Fixed in 3.0.0
Event History
Frequently Asked Questions
Which deployments are in scope?
FluentAuth versions through 2.1.2 are identified as affected. The provided data does not identify an unaffected fixed version.
Does exploitation require an authenticated account or user interaction?
No. The CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What is the expected security impact?
The issue is described as enabling identity spoofing. The CVSS vector indicates low integrity impact and no confidentiality or availability impact.