Impact
The Event Booking Manager for WooCommerce plugin allows authenticated users with contributor-level access and above to alter global payment settings, such as WooCommerce payment enablement, cart redirection, login requirements for checkout, and ticket status configuration. This occurs because the plugin fails to verify that the user has the appropriate capability before processing the mep_save_payment_settings_modal AJAX action. The vulnerability falls under CWE-862 and could be used to manipulate checkout flows or disable payments, impacting merchant revenue and customer experience.
Affected Systems
Mage People Team’s Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin, versions 5.3.7 and earlier.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score is below 1%, suggesting low exploitation probability under current conditions. The vulnerability is not listed in CISA’s KEV catalog. An attacker needs to be authenticated with contributor or higher privileges, and can exploit the insecure mep_save_payment_settings_modal endpoint to switch payment options or redirect carts, potentially disabling payments or altering checkout behavior.
OpenCVE Enrichment