CVE-2025-13756: Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution <= 1.9.11 - Authenticated (Subscriber+) Missing Authorization to Calendar Import and Management
The Fluent Booking plugin for WordPress is vulnerable to unauthorized calendar import and management due to a missing capability check on the "importCalendar" function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with subscriber level access and above, to import arbitrary calendars and manage them.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13756?
The severity of CVE-2025-13756 is considered to be high due to the potential for unauthorized access to calendar management functions.
How do I fix CVE-2025-13756?
To fix CVE-2025-13756, update the Fluent Booking plugin to version 1.10.0 or later, which includes the necessary capability checks.
Who is affected by CVE-2025-13756?
Authenticated users with subscriber roles who are using Fluent Booking plugin versions up to and including 1.9.11 are affected by CVE-2025-13756.
What action can attackers take due to CVE-2025-13756?
Attackers exploiting CVE-2025-13756 can import and manage calendars without proper authorization.
When was CVE-2025-13756 reported?
CVE-2025-13756 was reported prior to the release of version 1.10.0 of the Fluent Booking plugin.