VYPR

Event Booking Manager for WooCommerce

by WordPress

CVEs (7)

  • CVE-2026-16062MedAug 2, 2026
    risk 0.43cvss 6.6epss 0.00

    The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in…

  • CVE-2026-16064MedAug 2, 2026
    risk 0.35cvss 5.4epss 0.00

    The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and…

  • CVE-2026-16063MedAug 2, 2026
    risk 0.35cvss 5.4epss 0.00

    The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author role and above to…

  • CVE-2026-16067MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re-deriving the event's configured price.…

  • CVE-2026-91019MedSep 17, 2026
    risk 0.32cvss 4.9epss 0.00

    The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.

  • CVE-2026-91008LowSep 17, 2026
    risk 0.24cvss 3.7epss 0.00

    The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name,…

  • CVE-2026-17166MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is…