Junglewise Threat Intelligence

CVE-2026-78272: Fluent Support Pro broken access control vulnerability

CVE-2026-78272 · Severity: medium · CVSS 5.4 · Published 2026-08-24

Vendors: WP ManageNinja LLC.

Executive brief

Fluent Support Pro is a WordPress plugin used to manage customer support tickets and interactions. A broken access control vulnerability in versions 2.3.1 and earlier allows subscribers with low-level permissions to view and potentially access data or perform actions they should not be authorized for, such as viewing other users' support tickets or information.

Technical details

The vulnerability is a broken access control (OWASP A1) issue in Fluent Support Pro affecting versions up to 2.3.1. Subscriber-level users can access or perform actions beyond their intended authorization scope. The attack requires an authenticated subscriber account but does not require network pivoting or special conditions beyond normal plugin interaction. An attacker with a low-privilege subscriber account can exploit this to view unauthorized data or execute unauthorized actions. The vulnerability has been patched in version 2.3.2.

Affected products

  • WP ManageNinja LLC Fluent Support Pro <= 2.3.1

Timeline

  • 2026-08-24: disclosed: Published by Patchstack
  • 2026-08-24: patched: Fixed in version 2.3.2
  • 2026-08-13: other: Reported by Ananda Dhakal (Patchstack)

References

Related threats