CVE-2026-91008
Event Booking Manager for WooCommerce < 5.3.8 - Unauthenticated Attendee PII Disclosure via Booking Confirmation Panel
CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom registration fields) by supplying an enumerable booking reference. Exploitation is limited to sites configured to use the Event Booking Manager for WooCommerce WordPress plugin before 5.3.8's native (non-WooCommerce) checkout, which is not the default.
| Vendor | unknown |
| Product | event booking manager for woocommerce |
| Published | Sep 17, 2026 |
| Last Updated | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown event booking manager for woocommerce
Be the first to know when new low vulnerabilities affecting unknown event booking manager for woocommerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Event Booking Manager for WooCommerce
5.3.6 < 5.3.8
References
Credits
Usama Arshad WPScan