Description
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and pages on the site, including content they do not own.
Published: 2026-08-02
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Event Booking Manager for WooCommerce plugin contains a flaw where quick‑edit functions only confirm a global capability rather than verifying that a user is allowed to modify the specific event object. As a result, anyone with the Contributor role or higher can change the title and publish status of any post or page on the site, regardless of ownership. This omission enables unauthorized defacement, removal, or alteration of content across the site.

Affected Systems

WordPress sites installing the Event Booking Manager for WooCommerce plugin with a version earlier than 5.3.7 are affected. The vulnerability applies to all installations where the Contributor role is present, including default or custom roles possessing edit or publish capabilities.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. Because the flaw requires authenticated access with a Contributor or higher role and relies on internal admin interfaces, the attack surface is limited to users who can log in. The vulnerability is not listed in CISA’s KEV catalog. In the event of exploitation, an attacker could manipulate arbitrary post content, potentially defacing the site or disrupting legitimate content.

Generated by OpenCVE AI on August 4, 2026 at 23:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the plugin to version 5.3.7 or newer, which fixes the authorization check on event quick edits.
  • If a version upgrade is not immediately possible, remove or limit the Contributor role’s capabilities to edit and publish posts and pages, or replace the role with a custom role that does not include those capabilities.
  • As a temporary measure, disable the mpwem_quick_edit_event feature by adding a custom code snippet or using a security plugin that restricts quick edits for non‑administrator users.

Generated by OpenCVE AI on August 4, 2026 at 23:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Mon, 03 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sun, 02 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and pages on the site, including content they do not own.
Title Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification via mpwem_quick_edit_event
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-03T17:48:20.501Z

Reserved: 2026-07-17T12:58:58.934Z

Link: CVE-2026-16064

cve-icon Vulnrichment

Updated: 2026-08-03T17:48:16.952Z

cve-icon NVD

Status : Received

Published: 2026-08-02T06:16:38.983

Modified: 2026-08-03T19:16:44.153

Link: CVE-2026-16064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T23:30:15Z

Weaknesses