PT-2026-63329 · WordPress · Events Booking
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Events Booking versions 5.0.0 through 5.8.1
Description
An incorrect Access Control List (ACL) check—a mechanism used to define permissions for users—allows an actor to download invoice information without proper verification of their authorization.
Recommendations
Update Events Booking to version 5.8.1 or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Events Booking