CVE-2026-16064
Received Received - Intake

Authorization Bypass in Event Booking Manager for WooCommerce

Vulnerability report for CVE-2026-16064, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-02

Last updated on: 2026-08-02

Assigner: WPScan

Description

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and pages on the site, including content they do not own.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-02
Last Modified
2026-08-02
Generated
2026-08-02
AI Q&A
2026-08-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_event_booking_manager wp_event_booking_manager to 5.3.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Event Booking Manager for WooCommerce WordPress plugin before version 5.3.7. It allows users with Contributor role or higher to modify the title and publication status of any post or page on the site without proper authorization checks. The plugin fails to verify permissions on the specific object being edited, only checking a general capability.

Detection Guidance

Check if the Event Booking Manager for WooCommerce plugin is installed and verify its version. If it is below 5.3.7, the vulnerability may be present. Inspect WordPress user roles for Contributors or higher with unexpected modification permissions.

Impact Analysis

If exploited, this vulnerability could allow unauthorized users to change the content or status of posts and pages they do not own. This might lead to misinformation, defacement of public pages, or disruption of site operations. Sensitive or private content could be exposed or altered without permission.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized users to modify content they do not own. Unauthorized changes to posts or pages may lead to data integrity issues, unauthorized disclosure of sensitive information, or improper handling of personal data, which are key concerns under GDPR and HIPAA.

Mitigation Strategies

Update the Event Booking Manager for WooCommerce plugin to version 5.3.7 or later. Review and restrict user roles to ensure Contributors cannot modify posts or pages they do not own. Remove unnecessary elevated permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16064. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart