Fluent Booking
Fluent Booking: vulnerabilidades y CVE
Fluent Booking tiene 3 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE3
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-9576 | Media (4.9) | 0.40% | — | 30 jun 2026 | The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users with at least the Calendar Manager role to… |
| CVE-2026-57638 | Media (6.5) | 0.22% | — | 26 jun 2026 | Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions. |
| CVE-2025-13756 | Media (4.3) | 0.19% | — | 3 dic 2025 | The Fluent Booking plugin for WordPress is vulnerable to unauthorized calendar import and management due to a missing capability check on the "importCalendar" function in all versions up to, and including, 1.9.11. This… |