CVE Explorer
CVE-2026-9576
The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users with at least the Calendar Manager role to retrieve attendees' PII (name, email, phone, address, payment information) from calendar groups they do not own.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Fluent Booking","vendor":"Unknown","versions":[{"lessThan":"2.1.2","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e9ec6c5671b115357f9f9d83f7e8ab8a69e5d0076a30101f8c81347f450c297f · sha256:7134df5418dfd50b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e9ec6c5671b115357f9f9d83f7e8ab8a69e5d0076a30101f8c81347f450c297f · sha256:7134df5418dfd50b… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"description":"CWE-200 Information Exposure","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e9ec6c5671b115357f9f9d83f7e8ab8a69e5d0076a30101f8c81347f450c297f · sha256:7134df5418dfd50b… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/f28759e0-f15e-4014-b0d1-8b58bf412b49/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e9ec6c5671b115357f9f9d83f7e8ab8a69e5d0076a30101f8c81347f450c297f · sha256:7134df5418dfd50b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.