Unrated severityNVD Advisory· Published Sep 17, 2026
CVE-2026-91019
CVE-2026-91019
Description
The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <5.6.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.