Executive brief
Fluent Support Pro is a WordPress plugin providing customer support ticketing functionality. An unauthenticated cross-site request forgery vulnerability allows attackers to trick logged-in users into performing unintended actions, such as changing settings or creating support tickets, by redirecting them to malicious pages.
Technical details
The vulnerability is a cross-site request forgery (CSRF) flaw affecting Fluent Support Pro versions up to 2.3.1 that lacks proper CSRF token validation. An unauthenticated attacker can craft a malicious webpage or email containing a forged request that, when visited or interacted with by an authenticated user, causes unintended actions within the plugin. Exploitation requires user interaction (e.g., clicking a link or visiting a crafted page) and a victim who is logged into WordPress. The vulnerability has been patched in version 2.3.2 and later.
Affected products
- WP ManageNinja LLC Fluent Support Pro <= 2.3.1
Timeline
- 2026-08-24: disclosed: Published by Patchstack