PatchSiren cyber security CVE debrief
CVE-2026-91008 Event Booking Manager for WooCommerce CVE debrief
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 allows unauthenticated attackers to retrieve registered attendees' personal information by supplying an enumerable booking reference. This issue is limited to sites using the plugin's native checkout. The vulnerability enables attackers to access sensitive information including full names, email addresses, phone numbers, and custom registration fields of registered attendees. Defenders should assess the exposure of their WordPress sites and verify if they are using a vulnerable version of the plugin.
- Vendor
- Event Booking Manager for WooCommerce
- Product
- Event Booking Manager for WooCommerce
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-17
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-17
- Advisory updated
- 2026-09-18
Who should care
Defenders of WordPress sites using the Event Booking Manager for WooCommerce plugin should assess exposure and verify their version. Site administrators, security teams, and operators of WordPress environments where the plugin is active need to be aware of the potential for unauthorized access to sensitive attendee information. This includes reviewing the plugin version, assessing the exposure of registered attendees' personal information, and taking steps
Why it matters
CVE-2026-91008 allows unauthenticated attackers to retrieve registered attendees' personal information from WordPress sites using a vulnerable version of the Event Booking Manager for WooCommerce plugin. Defenders should assess exposure, verify their version, and restrict access to booking details.
- Verify if the site uses a vulnerable version of the Event Booking Manager for WooCommerce plugin
- Assess the exposure of registered attendees' personal information
- Restrict access to booking details to authorized users only
- Update the plugin to version 5.3.8 or later if vulnerable
Technical summary
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details. This allows unauthenticated attackers to retrieve registered attendees' personal information by supplying an enumerable booking reference. The plugin's native checkout feature is affected, but not the WooCommerce checkout. The vulnerability can be exploited to access sensitive information of registered attendees, including their full names, email addresses, phone numbers, and custom registration fields.
Defensive priority
Assess exposure and verify version; restrict access to booking details
Recommended defensive actions
- Assess exposure by checking if the Event Booking Manager for WooCommerce plugin version is before 5.3.8
- Verify if the site uses the plugin's native checkout
- Restrict access to booking details to authorized users only
- Update the plugin to version 5.3.8 or later if vulnerable
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. A source reference from WPScan offers additional context. The vulnerability has been confirmed in versions prior to 5.3.8 of the Event Booking Manager for WooCommerce WordPress plugin. Exploitation is limited to sites configured to use the plugin's native checkout. Defenders should verify their plugin version and assess exposure to this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-91008 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-91008
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-91008 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-91008
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/f3bcee4d-06b8-40bd-a4e6-91c671f405c6/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.