Unrated severityNVD Advisory· Published Aug 2, 2026· Updated Aug 3, 2026
Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification via mpwem_quick_edit_event
CVE-2026-16064
Description
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and pages on the site, including content they do not own.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <5.3.7
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/881ba365-b2ce-41e1-92bb-e5fa275f8a06/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.