CVE-2026-16062
Received Received - Intake

PHP Object Injection in Event Booking Manager for WooCommerce

Vulnerability report for CVE-2026-16062, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-02

Last updated on: 2026-08-02

Assigner: WPScan

Description

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 itself, but if one is present via another installed Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 or , this could lead to actions such as arbitrary file deletion, sensitive data retrieval, or remote code execution. This is an incomplete fix of the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7's earlier object-injection advisories.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-02
Last Modified
2026-08-02
Generated
2026-08-02
AI Q&A
2026-08-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_event_booking_manager plugin to 5.3.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the Event Booking Manager for WooCommerce WordPress plugin before version 5.3.7. It allows users with Contributor-level access or higher to inject PHP objects through event content fields due to improper deserialization of user-controlled input. While no proof-of-concept chain exists within the plugin itself, an external chain could lead to severe actions like arbitrary file deletion, sensitive data retrieval, or remote code execution.

Detection Guidance

This vulnerability requires checking for the Event Booking Manager for WooCommerce plugin version before 5.3.7. Inspect installed WordPress plugins via the WordPress admin panel or database. Use commands like 'wp plugin list' in WP-CLI or check the plugin directory for the vulnerable version.

Impact Analysis

If exploited, this vulnerability could allow attackers with Contributor-level access to perform destructive actions such as deleting files, stealing sensitive data, or executing arbitrary code on the affected WordPress site. This could lead to complete site compromise, data breaches, or unauthorized system access.

Compliance Impact

This vulnerability could lead to data breaches, exposing personal or sensitive information. This may result in non-compliance with regulations like GDPR or HIPAA, potentially leading to legal penalties, fines, or reputational damage due to unauthorized data access or loss.

Mitigation Strategies

Update the Event Booking Manager for WooCommerce WordPress plugin to version 5.3.7 or later to address the deserialization issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16062. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart