CVE-2026-9576

MEDIUM

Fluent Booking < 2.1.2 - Calendar Manager+ Sensitive Information Disclosure via Attendee Export

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-9576. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-9576, an information leak vulnerability in the Fluent Booking WordPress plugin (before 2.1.2). The module includes placeholder code for checking target connectivity but lacks actual exploit implementation for the described auth bypass flaw.

Description

The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users with at least the Calendar Manager role to retrieve attendees' PII (name, email, phone, address, payment information) from calendar groups they do not own.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-9576_the_fluent_booking.py

This repository contains an auto-generated stub module for CVE-2026-9576, an information leak vulnerability in the Fluent Booking WordPress plugin (before 2.1.2). The module includes placeholder code for checking target connectivity but lacks actual exploit implementation for the described auth bypass flaw.

Classification
Stub 99%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Theoretical
Target: Fluent Booking WordPress plugin before 2.1.2
Auth required
Prerequisites: WordPress site with vulnerable Fluent Booking plugin · Valid WordPress user account with Calendar privileges · Network access to target WordPress instance
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/f28759e0-f15e-4014-b0d1-8b58bf412b49/

Scores

CVSS v3 4.9
EPSS 0.0023
EPSS Percentile 14.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

Status published
Products (1)
None/Fluent Booking < 2.1.2
Published Jun 30, 2026
Tracked Since Jun 30, 2026