Cross Site Request Forgery Vulnerability in FluentBooking Pro by Fluent
CVE-2026-81273

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 August 2026

What is CVE-2026-81273?

FluentBooking Pro versions up to 2.2.4 are susceptible to unauthenticated Cross Site Request Forgery (CSRF) attacks, allowing attackers to perform unauthorized actions on behalf of users. This vulnerability can lead to security breaches if exploited, enabling malicious actors to potentially manipulate user data or settings without proper authentication. It is crucial for users to update to the latest version to mitigate these risks. For more information, refer to the detailed report on Patchstack.

Affected Version(s)

FluentBooking Pro <= 2.2.4

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.