Description
Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.
Published: 2026-09-03
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unpatched versions of the WordPress FluentBooking Pro plugin from 2.2.1 and earlier allow an unauthenticated attacker to bypass standard authentication controls. This flaw permits casual access to the plugin’s protected functions without credentials. The vulnerability stems from improper authentication, as identified by CWE‑290.

Affected Systems

The vulnerability affects the WP Manage Ninja FluentBooking Pro WordPress plugin for all users running any installed version through 2.2.1. Versions 2.3.0 and newer are not affected.

Risk and Exploitability

The advisory lists a CVSS score of 5.9, indicating a moderate risk. EPSS is not available, and the issue is not in the CISA KEV catalog, suggesting limited reported exploitation. The attack likely exploits the plugin’s authentication bypass privilege, and any visitor to the site could trigger it, so the attack vector is inferred as network‑based traffic to the hosting environment.

Generated by OpenCVE AI on September 3, 2026 at 20:37 UTC.

Remediation

Vendor Solution

Update the WordPress FluentBooking Pro Plugin to the latest available version (at least 2.3.0).


OpenCVE Recommended Actions

  • Update the FluentBooking Pro plugin to version 2.3.0 or newer.
  • If an update cannot be applied immediately, disable the FluentBooking Pro plugin or restrict access to booking functions until the patch is installed.
  • Review user roles and permissions for the booking system to ensure the least privilege principle is enforced.

Generated by OpenCVE AI on September 3, 2026 at 20:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.
Title WordPress FluentBooking Pro plugin <= 2.2.1 - Bypass Vulnerability vulnerability
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-05T01:51:20.874Z

Reserved: 2026-09-02T09:57:42.761Z

Link: CVE-2026-84766

cve-icon Vulnrichment

Updated: 2026-09-05T01:51:06.182Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T17:17:27.753

Modified: 2026-09-05T02:17:18.223

Link: CVE-2026-84766

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T20:45:05Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing