The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users with at least the Calendar Manager role to retrieve attendees' PII (name, email, phone, address, payment information) from calendar groups they do not own.
Metrics
Affected Vendors & Products
References
History
Tue, 30 Jun 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-284 |
Tue, 30 Jun 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users with at least the Calendar Manager role to retrieve attendees' PII (name, email, phone, address, payment information) from calendar groups they do not own. | |
| Title | Fluent Booking < 2.1.2 - Calendar Manager+ Sensitive Information Disclosure via Attendee Export | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-06-30T06:00:02.028Z
Reserved: 2026-05-26T12:45:23.442Z
Link: CVE-2026-9576
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-30T08:30:04Z