PT-2026-53823 · WordPress · Fluent Booking
CVE-2026-9576
·
Published
2026-06-30
·
Updated
2026-06-30
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Fluent Booking WordPress plugin versions prior to 2.1.2
Description
Users with at least the Calendar Manager role can retrieve personally identifiable information (PII), including names, emails, phone numbers, addresses, and payment information, from calendar groups they do not own. This occurs because the software fails to verify ownership of the requested
group id when exporting attendee data via the export endpoint.Recommendations
Update Fluent Booking WordPress plugin to version 2.1.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fluent Booking