PT-2026-67094 · Woocommerce · Event Booking Manager For Woocommerce
CVE-2026-16064
·
Published
2026-08-02
·
Updated
2026-08-02
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Event Booking Manager for WooCommerce versions prior to 5.3.7
Description
Insufficient authorization verification occurs when quick-editing events, as the system only checks a global capability rather than verifying permissions for the specific object being modified. This allows users with the Contributor role and above to modify the title and publication status of arbitrary posts and pages on the site, including content they do not own, via the
mpwem quick edit event() function.Recommendations
Update Event Booking Manager for WooCommerce to version 5.3.7 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Event Booking Manager For Woocommerce