Impact
Unpatched versions of the WordPress FluentBooking Pro plugin from 2.2.1 and earlier allow an unauthenticated attacker to bypass standard authentication controls. This flaw permits casual access to the plugin’s protected functions without credentials. The vulnerability stems from improper authentication, as identified by CWE‑290.
Affected Systems
The vulnerability affects the WP Manage Ninja FluentBooking Pro WordPress plugin for all users running any installed version through 2.2.1. Versions 2.3.0 and newer are not affected.
Risk and Exploitability
The advisory lists a CVSS score of 5.9, indicating a moderate risk. EPSS is not available, and the issue is not in the CISA KEV catalog, suggesting limited reported exploitation. The attack likely exploits the plugin’s authentication bypass privilege, and any visitor to the site could trigger it, so the attack vector is inferred as network‑based traffic to the hosting environment.
OpenCVE Enrichment