Junglewise Threat Intelligence

CVE-2026-78279: Fluent Support Pro unauthenticated cross-site request forgery

CVE-2026-78279 · Severity: medium · CVSS 5.4 · Published 2026-08-24

Vendors: WP ManageNinja LLC.

Executive brief

Fluent Support Pro is a WordPress plugin providing customer support ticketing functionality. An unauthenticated cross-site request forgery vulnerability allows attackers to trick logged-in users into performing unintended actions, such as changing settings or creating support tickets, by redirecting them to malicious pages.

Technical details

The vulnerability is a cross-site request forgery (CSRF) flaw affecting Fluent Support Pro versions up to 2.3.1 that lacks proper CSRF token validation. An unauthenticated attacker can craft a malicious webpage or email containing a forged request that, when visited or interacted with by an authenticated user, causes unintended actions within the plugin. Exploitation requires user interaction (e.g., clicking a link or visiting a crafted page) and a victim who is logged into WordPress. The vulnerability has been patched in version 2.3.2 and later.

Affected products

  • WP ManageNinja LLC Fluent Support Pro <= 2.3.1

Timeline

  • 2026-08-24: disclosed: Published by Patchstack

References

Related threats