Impact
The vulnerability arises because the plugin fails to verify that the requester owns or is authorized for the booking before displaying confirmation details. As a result, anyone who can guess or enumerate a booking reference can obtain the registered attendee’s full name, email address, phone number, and any custom registration fields. The weakness is a classic authorization bypass that exposes sensitive personal data.
Affected Systems
WordPress sites running Event Booking Manager for WooCommerce with version 5.3.7 or earlier, and that have enabled the plugin’s native checkout mode rather than the standard WooCommerce checkout. Sites using newer plugin releases or the default checkout are not affected.
Risk and Exploitability
The CVSS score of 3.7 reflects a moderate disclosure risk, while the EPSS score of less than 1% indicates a very low probability that attackers are currently exploiting this vulnerability in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a publicly accessible HTTP request with a valid booking reference, so the attack vector is likely network-based. Because the flaw allows attackers to retrieve data from any booking record that can be enumerated, the confidentiality impact is significant for affected users, though the overall system remains intact.
OpenCVE Enrichment