Executive brief
Fluent Booking is a WordPress plugin used to manage appointments and scheduling. A security vulnerability allows users with 'Contributor' level access to inject malicious scripts into the website. If a site administrator views the affected content, these scripts could execute, potentially leading to unauthorized actions, website defacement, or redirection of visitors to malicious sites.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Fluent Booking plugin for WordPress (versions <= 2.1.0). The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with 'Contributor' level privileges can inject malicious JavaScript payloads into the application. The vulnerability requires a victim (typically an administrator) to interact with the malicious content for the script to execute in their browser context. This can lead to session hijacking or unauthorized administrative actions. The issue is resolved in version 2.1.1.
Affected products
- WPManageNinja LLC Fluent Booking <= 2.1.0
Timeline
- 2026-02-09: other: Reported by Tarcísio Luchesi (Poystick)
- 2026-06-26: advisory: Published by Patchstack and NVD
- 2026-06-26: patched: Patch available in version 2.1.1