CVE-2026-81273: WordPress FluentBooking Pro plugin <= 2.2.4 - Cross Site Request Forgery (CSRF) vulnerability
Published Aug 27, 2026
·Updated
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
Affected Software
1 affected component
wordpress/fluent-booking-pro<=2.2.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress FluentBooking Pro pluginto a version that resolves this vulnerability.Fixed in 2.2.5
Event History
Aug 27, 2026
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Sites using FluentBooking Pro version 2.2.4 or earlier are affected according to the available data. Exploitation is network-accessible and does not require the attacker to authenticate.
2
What does an attacker need to exploit it?
The attacker needs to cause a user to interact with a malicious request, as indicated by the required user interaction in the CVSS vector. No attacker privileges are required.