Executive brief
FluentAuth is a WordPress authentication and security plugin that manages user authorization for WordPress sites. A flaw in how the plugin verifies the authenticity of user data allows attackers to spoof user identities without proper authentication, potentially enabling unauthorized access to accounts or administrative functions. This could lead to account takeover, data theft, or site compromise depending on the attacker's intended target.
Technical details
The vulnerability is classified as insufficient verification of data authenticity (CWE-345), which allows attackers to bypass authentication checks in FluentAuth. The flaw exists in versions up to 2.1.2 and enables identity spoofing—attackers can forge or manipulate authentication tokens or session data without proper verification. No special privileges or user interaction is required; the attack is network-accessible and can be exploited by unauthenticated attackers. The vulnerability has been patched in version 3.0.0 or later. The CVSS 5.3 score reflects medium severity impact, suggesting data integrity or availability concerns rather than complete system compromise.
Affected products
- WP ManageNinja LLC FluentAuth through 2.1.2
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Version 3.0.0 or later