VYPR

Event Booking Manager for WooCommerce

by WordPress

CVEs (4)

  • CVE-2026-16064Aug 2, 2026
    risk 0.00cvss epss 0.00

    The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and…

  • CVE-2026-16063Aug 2, 2026
    risk 0.00cvss epss 0.00

    The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author role and above to…

  • CVE-2026-16062Aug 2, 2026
    risk 0.00cvss epss 0.00

    The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in…

  • CVE-2026-17166Jul 29, 2026
    risk 0.00cvss epss 0.00

    The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is…