Impact
The Event Booking Manager for WooCommerce plugin before version 5.6.0 does not restrict read access to its stored payment gateway configuration. As a result, any user with Contributor role or higher can view the site's PayPal and Stripe settings, including secret keys. This flaw is an access control vulnerability (CWE-284) that compromises the confidentiality of sensitive financial credentials.
Affected Systems
Affected systems are WordPress installations that use the Event Booking Manager for WooCommerce plugin version prior to 5.6.0. The plugin is distributed under the ‘Unknown:Event Booking Manager for WooCommerce’ identifier. Users with Contributor or higher roles on any impacted site may be able to retrieve the credentials.
Risk and Exploitability
The CVSS score of 4.9 places the vulnerability in the medium severity range, while the EPSS score of less than 1% indicates a low probability of widespread exploitation. The risk is limited to sites where an attacker can gain or already possesses Contributor-level access. Since the vulnerability only allows confidential data disclosure and not code execution, it does not qualify for CISA KEV. The most likely attack path is an authenticated attacker using a legitimate Contributor account to view the payment gateway configuration through the WordPress admin interface.
OpenCVE Enrichment