PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-91008 Event Booking Manager for WooCommerce CVE debrief

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 allows unauthenticated attackers to retrieve registered attendees' personal information by supplying an enumerable booking reference. This issue is limited to sites using the plugin's native checkout. The vulnerability enables attackers to access sensitive information including full names, email addresses, phone numbers, and custom registration fields of registered attendees. Defenders should assess the exposure of their WordPress sites and verify if they are using a vulnerable version of the plugin.

Vendor
Event Booking Manager for WooCommerce
Product
Event Booking Manager for WooCommerce
CVSS
LOW 3.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-18
Advisory published
2026-09-17
Advisory updated
2026-09-18

Who should care

Defenders of WordPress sites using the Event Booking Manager for WooCommerce plugin should assess exposure and verify their version. Site administrators, security teams, and operators of WordPress environments where the plugin is active need to be aware of the potential for unauthorized access to sensitive attendee information. This includes reviewing the plugin version, assessing the exposure of registered attendees' personal information, and taking steps

Why it matters

CVE-2026-91008 allows unauthenticated attackers to retrieve registered attendees' personal information from WordPress sites using a vulnerable version of the Event Booking Manager for WooCommerce plugin. Defenders should assess exposure, verify their version, and restrict access to booking details.

  • Verify if the site uses a vulnerable version of the Event Booking Manager for WooCommerce plugin
  • Assess the exposure of registered attendees' personal information
  • Restrict access to booking details to authorized users only
  • Update the plugin to version 5.3.8 or later if vulnerable

Technical summary

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details. This allows unauthenticated attackers to retrieve registered attendees' personal information by supplying an enumerable booking reference. The plugin's native checkout feature is affected, but not the WooCommerce checkout. The vulnerability can be exploited to access sensitive information of registered attendees, including their full names, email addresses, phone numbers, and custom registration fields.

Defensive priority

Assess exposure and verify version; restrict access to booking details

Recommended defensive actions

  • Assess exposure by checking if the Event Booking Manager for WooCommerce plugin version is before 5.3.8
  • Verify if the site uses the plugin's native checkout
  • Restrict access to booking details to authorized users only
  • Update the plugin to version 5.3.8 or later if vulnerable
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. A source reference from WPScan offers additional context. The vulnerability has been confirmed in versions prior to 5.3.8 of the Event Booking Manager for WooCommerce WordPress plugin. Exploitation is limited to sites configured to use the plugin's native checkout. Defenders should verify their plugin version and assess exposure to this vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-91008 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-91008

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-91008 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-91008

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.