The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and pages on the site, including content they do not own.
ReviewEvent Booking Manager for WooCommerceCVE published 2026-08-02
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author role and above to inject arbitrary JavaScript that executes in the browser of any visitor viewing the event, including administrators.
ReviewEvent Booking Manager for WooCommerceCVE published 2026-08-02
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent deserialization of user-controlled input in some event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in the plugin itself, but if one is present via another installed plugin, this could lead to actions such as arbitrary file deletion, sensitive da [truncated]