PT-2026-67094 · Woocommerce · Event Booking Manager For Woocommerce

CVE-2026-16064

·

Published

2026-08-02

·

Updated

2026-08-02

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Event Booking Manager for WooCommerce versions prior to 5.3.7
Description Insufficient authorization verification occurs when quick-editing events, as the system only checks a global capability rather than verifying permissions for the specific object being modified. This allows users with the Contributor role and above to modify the title and publication status of arbitrary posts and pages on the site, including content they do not own, via the mpwem quick edit event() function.
Recommendations Update Event Booking Manager for WooCommerce to version 5.3.7 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16064

Affected Products

Event Booking Manager For Woocommerce