Executive brief
FluentBooking Pro is a WordPress plugin for managing booking functionality on websites. An unauthenticated cross-site request forgery (CSRF) vulnerability allows attackers to trick logged-in administrators into performing unintended actions, such as changing settings or modifying bookings, by redirecting them to malicious pages. Websites running affected versions are exposed to unauthorized changes without user awareness.
Technical details
This is a cross-site request forgery (CSRF) vulnerability in FluentBooking Pro versions up to 2.2.4 that lacks proper CSRF token validation. The vulnerability is unauthenticated in the sense that no attacker credentials are required; however, successful exploitation requires a privileged user (logged-in administrator) to be tricked into visiting a malicious page or clicking a crafted link that triggers unintended actions via forged requests. The attack vector is network-based and requires user interaction. The plugin was patched in version 2.2.5, which introduces proper CSRF protections.
Affected products
- WP ManageNinja LLC FluentBooking Pro <=2.2.4
Timeline
- 2026-08-13: disclosed: Reported to Patchstack
- 2026-08-26: patched: Patched in version 2.2.5
- 2026-08-27: advisory: Published on NVD