Impact
The Event Booking Manager for WooCommerce (Pro) plugin fails to re‑derive the configured ticket price on the server during its native checkout flow and instead accepts the per‑ticket price supplied by the client. This lack of server‑side validation allows an unauthenticated user to submit a booking request that uses any arbitrary price, effectively bypassing the payment requirement. The result is a completed booking and valid tickets that the attacker obtains for free, with potential financial loss for the site owner.
Affected Systems
All installations of the Event Booking Manager for WooCommerce (Pro) with a plugin version earlier than 5.0.3 are impacted. These installations provide a native checkout route that is not protected by authentication checks for ticket pricing.
Risk and Exploitability
The vulnerability is rated with a CVSS score of 5.3, indicating a moderate impact. The EPSS score is not available, so the current estimated exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly documented exploitation. An attacker can exploit the flaw by sending a crafted request to the native checkout endpoint as an unauthenticated user, posing any price value and receiving free tickets; no additional privileges are required.
OpenCVE Enrichment