CVE-2025-13756

MEDIUM

Fluent Booking <1.9.11 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The Fluent Booking plugin for WordPress is vulnerable to unauthorized calendar import and management due to a missing capability check on the "importCalendar" function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with subscriber level access and above, to import arbitrary calendars and manage them.

Scores

CVSS v3 4.3
EPSS 0.0016
EPSS Percentile 5.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
techjewel/Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution < 1.9.11
Published Dec 03, 2025
Tracked Since Feb 18, 2026