Impact
This vulnerability exists because the plugin's importCalendar function does not enforce a capability check. The flaw allows any authenticated user with at least the subscriber role to import arbitrary calendars and manage them, potentially leading to modification of event data, unauthorized scheduling, or exposure of calendar information. The weakness is classed as CWE-862 Missing Authorization.
Affected Systems
The affected product is the “Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution” plugin for WordPress, found in all releases up to and including version 1.9.11. Users running these versions with a subscriber or higher role are susceptible to the flaw.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score below 1% suggests a low likelihood of immediate exploitation. Since the flaw requires authenticated access and is not listed in the CISA KEV catalog, it is unlikely to be widely attacked. Attackers would need to log in as a subscriber or higher and then target the importCalendar endpoint directly. The risk is proportionate to the number of sites using vulnerable plugin versions and the nature of the data stored in the calendars.
OpenCVE Enrichment