Junglewise Threat Intelligence

CVE-2026-65470: WPManageNinja Fluent Support Contributor XSS

CVE-2026-65470 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Executive brief

Fluent Support is a WordPress plugin used for managing customer support tickets and help desks. A security vulnerability in versions 2.3.0 and earlier allows users with 'Contributor' level access to inject malicious scripts into the website. If an administrator or other site visitor views the affected content, these scripts could be used to redirect users to malicious sites, steal session information, or perform unauthorized actions on behalf of the victim.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the WPManageNinja Fluent Support plugin for WordPress (versions <= 2.3.0). The flaw is due to improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with 'Contributor' level privileges can inject malicious JavaScript payloads that are stored on the server. The attack requires a victim (typically an administrator) to interact with the affected page for the script to execute in their browser context. This can lead to session hijacking or unauthorized administrative actions. The issue is resolved in version 2.3.1.

Affected products

  • WPManageNinja Fluent Support <= 2.3.0

Timeline

  • 2026-07-09: disclosed: Reported by Ananda Dhakal via Patchstack
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: advisory: NVD published CVE-2026-65470
  • 2026-07-23: patched: Version 2.3.1 identified as unaffected version

References

Related threats