CVE-2026-91077
Received Received - Intake

Event Listing Information Disclosure in Event Booking Manager for WooCommerce

Vulnerability report for CVE-2026-91077, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WPScan

Description

The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level access and above can retrieve other authors' private, draft and trashed events, together with event detail the standard listing does not show them. This discloses private events and their content that WordPress withholds from users lacking the read_private_posts capability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wp_event_booking_manager wp_event_booking_manager to 5.7.3 (exc)
artus_kg event_booking_manager_for_woocommerce From 5.3.6 (inc) to 5.7.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Event Booking Manager for WooCommerce WordPress plugin. Users with contributor-level access or higher can retrieve private, draft, or trashed events belonging to other authors. The plugin fails to restrict event listing queries to only accessible events, exposing content that WordPress normally hides from unauthorized users.

Detection Guidance

To detect this vulnerability, check if your Event Booking Manager for WooCommerce plugin is running a vulnerable version (5.3.6 to 5.7.2). You can use WPScan to scan for vulnerable versions with the command: wp plugin list | grep event-booking-manager. Alternatively, inspect the plugin files for the mpwem_load_event_list function to verify if it restricts event access properly.

Impact Analysis

If you use the affected plugin versions, unauthorized users could view sensitive event details, including private or unpublished content. This could lead to data leaks, reputational damage, or unauthorized access to confidential information stored in events.

Compliance Impact

This vulnerability could violate compliance requirements by exposing private or sensitive data to unauthorized users. GDPR and HIPAA mandate strict access controls and data protection; unauthorized disclosure may result in legal penalties, fines, or loss of certification.

Mitigation Strategies

Immediately update the Event Booking Manager for WooCommerce plugin to version 5.7.3 or later. If updating is not possible, consider disabling the plugin temporarily until the update is applied. Review user roles and permissions to ensure contributors and higher-level users do not have unnecessary access to unpublished events.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91077. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart