SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16063

MEDIUM · CVSS 5.4 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

The Event Booking Manager for WooCommerce plugin prior to version 5.3.7 is vulnerable due to inadequate sanitization of event timeline content submitted by users with post-editing access. This flaw allows users with the Author role and higher to inject malicious JavaScript, which executes in the browsers of visitors, including administrators, potentially leading to cross-site scripting (XSS) attacks. WordPress site administrators and plugin maintainers should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-16063
Severity
MEDIUM
CVSS
5.4
EPSS
0.13%
WordPress Java

Original NVD Description

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author role and above to inject arbitrary JavaScript that executes in the browser of any visitor viewing the event, including administrators.