CVE-2026-94679: WordPress Fluent Support plugin <= 2.3.2 - Broken Access Control vulnerability
Published Sep 23, 2026
·Updated
Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.
Affected Software
1 affected component
Fluent Support Fluent Support<=2.3.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Fluent Support pluginto a version that resolves this vulnerability.Fixed in 2.4.0
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker needs a low-privileged authenticated account, such as a Subscriber. The attack can be performed remotely over the network and does not require user interaction.
2
Can this vulnerability affect site availability?
No availability impact is indicated. The reported impact is limited to low confidentiality and low integrity impact.