CVE-2026-9576
MEDIUMFluent Booking < 2.1.2 - Calendar Manager+ Sensitive Information Disclosure via Attendee Export
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-9576. PoCs published by HermesNA-1.
AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-9576, an information leak vulnerability in the Fluent Booking WordPress plugin (before 2.1.2). The module includes placeholder code for checking target connectivity but lacks actual exploit implementation for the described auth bypass flaw.
Description
The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users with at least the Calendar Manager role to retrieve attendees' PII (name, email, phone, address, payment information) from calendar groups they do not own.
Exploits (1)
This repository contains an auto-generated stub module for CVE-2026-9576, an information leak vulnerability in the Fluent Booking WordPress plugin (before 2.1.2). The module includes placeholder code for checking target connectivity but lacks actual exploit implementation for the described auth bypass flaw.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N