WordPress Plugin Vulnerabilities

Fluent Booking < 2.1.2 - Calendar Manager+ Sensitive Information Disclosure via Attendee Export

Description

The plugin does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users with at least the Calendar Manager role to retrieve attendees' PII (name, email, phone, address, payment information) from calendar groups they do not own.

Proof of Concept

Affects Plugins

Fixed in 2.1.2

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Md Amin Ullah Sheikh
Submitter
Md Amin Ullah Sheikh
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-06-09 (about 21 days ago)
Added
2026-06-09 (about 20 days ago)
Last Updated
2026-06-09 (about 20 days ago)

Other