Unauthenticated Broken Access Control in Fluent Affiliate Pro by WordPress
CVE-2026-39789
7.5HIGH
What is CVE-2026-39789?
Fluent Affiliate Pro versions up to 1.6.4 are susceptible to an unauthenticated broken access control vulnerability. This security flaw may allow unauthorized users to gain access to restricted functionalities or data within the application, potentially leading to unauthorized actions or data exposure. It is crucial for users of this plugin to update to a secure version promptly to mitigate any security risks.
Affected Version(s)
Fluent Affiliate Pro <= 1.6.4
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program