PatchSiren

Event Booking Manager for WooCommerce CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Event Booking Manager for WooCommerce CVE published 2026-08-02

CVE-2026-16064

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and pages on the site, including content they do not own.

Review Event Booking Manager for WooCommerce CVE published 2026-08-02

CVE-2026-16063

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author role and above to inject arbitrary JavaScript that executes in the browser of any visitor viewing the event, including administrators.

Review Event Booking Manager for WooCommerce CVE published 2026-08-02

CVE-2026-16062

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent deserialization of user-controlled input in some event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in the plugin itself, but if one is present via another installed plugin, this could lead to actions such as arbitrary file deletion, sensitive da [truncated]