Impact
An unauthenticated Cross Site Request Forgery flaw in FluentBooking Pro (CWE-352) allows an attacker to craft malicious requests that are executed by a victim’s browser while authenticated to the WordPress site. The flaw bypasses the plugin’s CSRF protections, enabling unauthorized booking actions such as creating, modifying, or deleting reservations. This carries a high potential impact on the confidentiality and integrity of booking data.
Affected Systems
The vulnerability affects WordPress installations that use WP Manage Ninja’s FluentBooking Pro plugin version 2.2.4 or earlier. Any site running these plugin versions is at risk if the plugin is enabled.
Risk and Exploitability
The CVSS score of 8.1 classifies this as high severity. EPSS data is not available, so exploitation likelihood cannot be quantified, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be via a crafted link or email that triggers a POST or GET request from the victim’s browser, exploiting the lack of CSRF validation. No authentication is required for exploitation.
OpenCVE Enrichment