Wpmanageninja Llc · Fluent Booking · CVE-2026-57638
**Name of the Vulnerable Software and Affected Versions**
Fluent Booking versions prior to 2.1.1
**Description**
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. This allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages, which execute when a user accesses the affected page.
**Recommendations**
Update to a version newer than 2.1.0.