Sceawere

Vulnerability Detail

CVE-2026-84766UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FluentBooking Pro Unauthenticated Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
4h ago
Vendor
WP Manage Ninja
Product
FluentBooking Pro
Attack Type
CWE-290 Authentication Bypass by Spoofing
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-09-03T17:17:27.753Z",
  "pubdate": "2026-09-03T17:17:27.753Z",
  "executiveSummary": "FluentBooking Pro versions 2.2.1 and below are susceptible to an unauthenticated bypass vulnerability. This security flaw allows remote, unauthenticated attackers to circumvent established authentication mechanisms, potentially gaining unauthorized access to protected functionalities within the plugin. The vulnerability stems from improper validation of request parameters or security tokens during the execution of booking-related routines. By leveraging this bypass, an adversary can perform actions restricted to legitimate users or administrators without possessing valid credentials. The risk profile is significant, as successful exploitation enables unauthorized system interaction, data exposure, and potential manipulation of booking workflows. This vulnerability does not require prior knowledge of the target system's user base, as the exposure occurs at the application layer before session validation is enforced. Organizations deploying FluentBooking Pro are urged to address this risk immediately to prevent potential compromise of sensitive booking data and operational integrity. Exploitation requires only network connectivity to the affected WordPress installation, making this a high-priority concern for system administrators.",
  "technicalDetails": "The vulnerability identified in FluentBooking Pro <= 2.2.1 is categorized as an authentication bypass mechanism resulting from improper access control enforcement within the plugin's request handling logic. The root cause lies in the insufficient verification of security tokens or nonces during the processing of specific API or AJAX endpoints designed for booking management. Because the authentication middleware fails to effectively validate the requester's authorization state before executing sensitive controller actions, the application processes requests as if they were initiated by an authenticated user.\nThe attack flow initiates when an attacker crafts a malicious HTTP request targeting the exposed FluentBooking Pro endpoints. By omitting or manipulating the expected authentication headers or parameters, the attacker exploits the lack of server-side validation. Upon reaching the vulnerable component, the application executes the requested operation—such as modifying booking entries, extracting appointment metadata, or accessing sensitive configuration data—without ever confirming the identity or privilege level of the requester.\nThe impact of this flaw is widespread across the plugin’s functional surface. Since the application fails to perform an authentication check at the entry point of the specific function, the exploitation vector is trivial for any remote attacker with network access to the target WordPress site. The vulnerability essentially renders existing ACLs (Access Control Lists) ineffective for the affected endpoints. Post-exploitation, an attacker can manipulate booking schedules, potentially leading to unauthorized reservation adjustments or the leakage of personally identifiable information (PII) stored within the booking database. Furthermore, if the bypassed functionality includes administrative capabilities, an attacker may achieve deeper persistence or execute administrative operations intended solely for privileged site operators. This bypass highlights a failure in the 'Secure by Default' design principle, where security checks must be universally applied across all sensitive server-side methods regardless of the perceived endpoint exposure."
}
CVE-2026-84766: FluentBooking Pro Unauthenticated Bypass Vulnerability (MEDIUM Severity, CVSS: 5.9) - Sceawere