VYPR

Fluent Booking

by WordPress

Source repositories

CVEs (5)

  • CVE-2026-2231HigMar 26, 2026
    risk 0.40cvss 7.2epss 0.00

    The Fluent Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 2.0.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

  • CVE-2025-67597MedDec 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Shahjahan Jewel Fluent Booking fluent-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Booking: from n/a through <= 1.9.11.

  • CVE-2025-13756MedDec 3, 2025
    risk 0.21cvss 4.3epss 0.00

    The Fluent Booking plugin for WordPress is vulnerable to unauthorized calendar import and management due to a missing capability check on the "importCalendar" function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with…

  • CVE-2026-9576MedJun 30, 2026
    risk 0.00cvss 4.9epss 0.00

    The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users with at least the Calendar Manager role to retrieve attendees' PII (name, email, phone, address, payment…

  • CVE-2026-57638MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions.