Description
Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions.
Published: 2026-10-06
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized Access
Action: Update
AI Analysis

Impact

A flaw in the FluentBooking Pro plugin for WordPress allows an unauthenticated attacker to bypass access controls and perform privileged operations, potentially reading or modifying booking data and other sensitive information. The weakness is categorized as CWE‑862 and results in the ability to act with elevated privileges without needing to authenticate, which can compromise confidentiality and integrity of booking data and site operations.

Affected Systems

Any WordPress site that has the FluentBooking Pro plugin installed in a version earlier than 2.5.0 is affected. The vulnerability affects all instances of the plugin regardless of whether the plugin is enabled for public or admin usage and applies to all sites running the specified vendor and product.

Risk and Exploitability

The CVSS score of 7.5 reflects a high severity vulnerability that is exploitable from the network by any visitor, as authentication is not required. No EPSS score is available, and the issue is not listed in CISA KEV; however, the lack of authentication checks makes exploitation straightforward. An attacker can craft requests to the plugin’s endpoints and gain unauthorized access to booking data and administrative actions.

Generated by OpenCVE AI on October 6, 2026 at 06:54 UTC.

Remediation

Vendor Solution

Update the WordPress FluentBooking Pro plugin to the latest available version (at least 2.5.0).


OpenCVE Recommended Actions

  • Update the FluentBooking Pro plugin to version 2.5.0 or later to apply the vendor’s fix for broken access control.
  • If the site cannot be upgraded immediately, block unauthenticated requests to the plugin’s endpoints (e.g., via web‑server configuration or a firewall) to prevent exploitation until the update is applied.
  • local and reverse‑proxy caches and restart the web server so that the new configuration and updated plugin files take effect.

Generated by OpenCVE AI on October 6, 2026 at 06:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions.
Title WordPress FluentBooking Pro plugin < 2.5.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-06T05:14:44.960Z

Reserved: 2026-10-03T00:17:03.679Z

Link: CVE-2026-105072

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T06:16:59.313

Modified: 2026-10-06T06:16:59.313

Link: CVE-2026-105072

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T07:00:14Z

Weaknesses