Description
The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to modify site-wide payment settings — including WooCommerce payment enablement, cart redirect behavior, login requirements for checkout, confirmation page ID, and confirmed ticket statuses — that govern how all event bookings are processed.
Published: 2026-07-29
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Event Booking Manager for WooCommerce plugin allows authenticated users with contributor-level access and above to alter global payment settings, such as WooCommerce payment enablement, cart redirection, login requirements for checkout, and ticket status configuration. This occurs because the plugin fails to verify that the user has the appropriate capability before processing the mep_save_payment_settings_modal AJAX action. The vulnerability falls under CWE-862 and could be used to manipulate checkout flows or disable payments, impacting merchant revenue and customer experience.

Affected Systems

Mage People Team’s Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin, versions 5.3.7 and earlier.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score is below 1%, suggesting low exploitation probability under current conditions. The vulnerability is not listed in CISA’s KEV catalog. An attacker needs to be authenticated with contributor or higher privileges, and can exploit the insecure mep_save_payment_settings_modal endpoint to switch payment options or redirect carts, potentially disabling payments or altering checkout behavior.

Generated by OpenCVE AI on August 3, 2026 at 14:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Event Booking Manager for WooCommerce plugin to a version newer than 5.3.7 to ensure the missing authorization check is added to the mep_save_payment_settings_modal AJAX action.
  • Verify that the update properly enforces capability checks before modifying global payment settings.
  • Review and reset any payment or checkout configuration changes that may have been made while the vulnerability was present.
  • Restrict contributor‑level users to only necessary capabilities or implement monitoring to detect unexpected changes to payment settings.

Generated by OpenCVE AI on August 3, 2026 at 14:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Magepeopleteam
Magepeopleteam event Booking Manager For Woocommerce – Sell Tickets, Event Registration, Rsvp & Event Calendar
Wordpress
Wordpress wordpress
Vendors & Products Magepeopleteam
Magepeopleteam event Booking Manager For Woocommerce – Sell Tickets, Event Registration, Rsvp & Event Calendar
Wordpress
Wordpress wordpress

Wed, 29 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Description The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to modify site-wide payment settings — including WooCommerce payment enablement, cart redirect behavior, login requirements for checkout, confirmation page ID, and confirmed ticket statuses — that govern how all event bookings are processed.
Title Event Booking Manager for WooCommerce <= 5.3.7 - Missing Authorization to Authenticated (Contributor+) Site-Wide Payment Settings Modification via mep_save_payment_settings_modal AJAX Action
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Magepeopleteam Event Booking Manager For Woocommerce – Sell Tickets, Event Registration, Rsvp & Event Calendar
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-29T12:56:46.107Z

Reserved: 2026-07-24T18:02:01.608Z

Link: CVE-2026-17166

cve-icon Vulnrichment

Updated: 2026-07-29T12:56:40.335Z

cve-icon NVD

Status : Deferred

Published: 2026-07-29T02:16:43.613

Modified: 2026-07-30T14:01:30.413

Link: CVE-2026-17166

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:15:05Z

Weaknesses