CVE-2026-78467: Fluent Support Pro <= 2.3.1 - Missing Authorization
The Fluent Support Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated to the WordPress site and have at least Subscriber-level access. Unauthenticated visitors are not described as able to exploit it.
Which installations are affected?
Fluent Support Pro versions through 2.3.1, including 2.3.1, are affected. The provided information does not identify a configuration prerequisite.
What impact can exploitation have?
A qualifying low-privileged user can perform an unauthorized action because the affected function lacks a capability check. The supplied severity vector indicates integrity impact only; no confidentiality or availability impact is specified.