Description
Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing.

This issue affects FluentAuth: from n/a through 2.1.2.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Update the WordPress FluentAuth – The Ultimate Authorization & Security Plugin for WordPress plugin to the latest available version (at least 3.0.0).

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2.
Title WordPress FluentAuth plugin <= 2.1.2 - Email Verification Bypass vulnerability
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-17T11:05:56.771Z

Reserved: 2026-08-24T07:38:18.806Z

Link: CVE-2026-78296

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T12:18:26.853

Modified: 2026-09-17T12:18:26.853

Link: CVE-2026-78296

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity