Impact
FluentAuth, a WordPress security plugin, permits attackers to bypass the email verification step, enabling them to impersonate any legitimate user. This weakness is an insufficient verification of data authenticity flaw, classified as CWE‑345, and can lead to full account takeover if an attacker succeeds in forging verification data.
Affected Systems
WordPress sites that use the FluentAuth plugin from WP ManageNinja LLC, including all releases up to and including version 2.1.2. No further specific sub‑versions are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available; the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is exploitation of the plugin’s email verification logic, where a malicious actor crafts or intercepts verification data to impersonate a user. While no public exploit is cited, the moderate score underscores that the vulnerability is actionable and should be remediated promptly.
OpenCVE Enrichment