CVE-2025-13756
BaseFortify
Publication date: 2025-12-03
Last updated on: 2025-12-04
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fluent_booking | fluent_booking | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability in the Fluent Booking plugin for WordPress allows authenticated users with subscriber level access or higher to import and manage calendars without proper authorization. This is due to a missing capability check on the "importCalendar" function in all versions up to and including 1.9.11, enabling unauthorized calendar import and management.
How can this vulnerability impact me? :
This vulnerability can allow attackers with low-level authenticated access to import arbitrary calendars and manage them, potentially leading to unauthorized manipulation of booking data or schedules. While it does not directly impact confidentiality or availability, it can affect the integrity of calendar data.