Impact
The vulnerability is an unauthenticated Cross Site Request Forgery flaw present in all releases of the Fluent Support Pro plugin through version 2.3.1. It allows an unauthenticated attacker to send crafted requests that the plugin will accept and execute as if they came from an authorized user, potentially altering the state of the plugin or the website without needing credentials. The impact is limited to the scope of actions the plugin supports, but it can compromise the integrity of the site by modifying data the plugin handles.
Affected Systems
WordPress sites that have installed WP ManageNinja LLC’s Fluent Support Pro plugin with version 2.3.1 or earlier.
Risk and Exploitability
The CVSS score of 5.4 rates this flaw as moderate severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog. The likely attack vector is a web‑based CSRF where an unauthenticated user is tricked into visiting a crafted page that submits a forged request to the vulnerable plugin.
OpenCVE Enrichment