Unauthenticated Bypass Vulnerability in FluentBooking Pro by WordPress
CVE-2026-84766
5.9MEDIUM
What is CVE-2026-84766?
The unauthenticated bypass vulnerability in FluentBooking Pro versions up to 2.2.1 allows unauthorized users to gain access and perform actions without proper authentication. This flaw could lead to significant security issues for sites using the affected plugin, potentially compromising sensitive data and site integrity. Users are advised to update to the latest version to mitigate any risks associated with this vulnerability.
Affected Version(s)
FluentBooking Pro <= 2.2.1
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program