PT-2026-97196 · Woocommerce · Event Booking Manager
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Event Booking Manager for WooCommerce versions prior to 5.7.3
Description
The plugin fails to restrict its event listing query to events that the requesting user is authorized to view. Consequently, users with contributor-level access or higher can retrieve private, draft, and trashed events created by other authors, including details not typically displayed in standard listings. This results in the disclosure of private event content that is normally restricted to users possessing the
read private posts capability.Recommendations
Update to version 5.7.3 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Event Booking Manager