SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16064

MEDIUM · CVSS 5.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

The Event Booking Manager for WooCommerce plugin in WordPress versions prior to 5.3.7 is vulnerable due to inadequate authorization checks during quick-editing of events, enabling users with Contributor roles and higher to alter titles and publication statuses of any posts and pages, including those they do not own. This could lead to unauthorized content manipulation and potential misinformation on the site. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-16064
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%
WordPress

Original NVD Description

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and pages on the site, including content they do not own.