Description
Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing.

This issue affects FluentAuth: from n/a through 2.1.2.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Account takeover via identity spoofing
Action: Immediate patch
AI Analysis

Impact

FluentAuth, a WordPress security plugin, permits attackers to bypass the email verification step, enabling them to impersonate any legitimate user. This weakness is an insufficient verification of data authenticity flaw, classified as CWE‑345, and can lead to full account takeover if an attacker succeeds in forging verification data.

Affected Systems

WordPress sites that use the FluentAuth plugin from WP ManageNinja LLC, including all releases up to and including version 2.1.2. No further specific sub‑versions are listed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available; the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is exploitation of the plugin’s email verification logic, where a malicious actor crafts or intercepts verification data to impersonate a user. While no public exploit is cited, the moderate score underscores that the vulnerability is actionable and should be remediated promptly.

Generated by OpenCVE AI on September 18, 2026 at 06:56 UTC.

Remediation

Vendor Solution

Update the WordPress FluentAuth – The Ultimate Authorization & Security Plugin for WordPress plugin to the latest available version (at least 3.0.0).


OpenCVE Recommended Actions

  • Upgrade FluentAuth to version 3.0.0 or later. This is the official solution published by the vendor.
  • Verify after the upgrade that the email verification process requires proper token validation and rejects any forged data.
  • If an immediate update cannot be performed, disable or restrict the email verification feature or block the plugin’s registration handling until the patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 06:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpmanageninja
Wpmanageninja fluentauth
Vendors & Products Wordpress
Wordpress wordpress
Wpmanageninja
Wpmanageninja fluentauth

Thu, 17 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2.
Title WordPress FluentAuth plugin <= 2.1.2 - Email Verification Bypass vulnerability
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Wpmanageninja Fluentauth
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-19T14:21:54.487Z

Reserved: 2026-08-24T07:38:18.806Z

Link: CVE-2026-78296

cve-icon Vulnrichment

Updated: 2026-09-19T14:17:14.111Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T12:18:26.853

Modified: 2026-09-19T15:17:02.303

Link: CVE-2026-78296

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:15Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity