Description
Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.
Published: 2026-07-23
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Contributor Cross Site Scripting has been identified in the WordPress Fluent Support plugin versions 2.3.0 and earlier. The flaw allows a user with contributor privileges to insert unsanitized scripts into the content managed by the plugin, which will then be executed in the browsers of visitors who view the affected page. This client‑side code execution can compromise the confidentiality and integrity of the site’s users by running arbitrary JavaScript in their context.

Affected Systems

All installations of the WPManageNinja Fluent Support plugin with a version of 2.3.0 or older on WordPress sites are vulnerable. The affected product is the Fluent Support plugin, version 2.3.0 or earlier.

Risk and Exploitability

The CVSS base score of 6.5 indicates a moderate impact, while the EPSS score of less than 1 percent suggests a very low likelihood of exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves a contributor account that can submit content; the exploiter would need a victim to visit a page that renders the injected script. No additional privileged access is required beyond the ability to add content.

Generated by OpenCVE AI on August 5, 2026 at 01:05 UTC.

Remediation

Vendor Solution

Update the WordPress Fluent Support Plugin to the latest available version (at least 2.3.1).


OpenCVE Recommended Actions

  • Upgrade the WordPress Fluent Support Plugin to version 2.3.1 or later.
  • If an immediate upgrade is not possible, temporarily disable the plugin or remove it from the active plugins list.
  • Restrict contributor capabilities to prevent the insertion of untrusted content, or apply input sanitization to all user‑generated content to block script injection.

Generated by OpenCVE AI on August 5, 2026 at 01:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpmanageninja
Wpmanageninja fluent Support
Vendors & Products Wordpress
Wordpress wordpress
Wpmanageninja
Wpmanageninja fluent Support

Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.
Title WordPress Fluent Support plugin <= 2.3.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Wpmanageninja Fluent Support
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T13:43:37.316Z

Reserved: 2026-07-22T08:53:23.247Z

Link: CVE-2026-65470

cve-icon Vulnrichment

Updated: 2026-07-23T13:43:30.584Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:39.723

Modified: 2026-07-23T14:17:50.573

Link: CVE-2026-65470

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')