Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High0
Medium0
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2026-08-02

CVE-2026-16064 - Event Booking Manager For Woocommerce Plugin

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and pages on the site, including content they do not own.

PLUGIN Event Booking Manager For Woocommerce

CVE-2026-16064

UNKNOWN CVSS 0.0 2026-08-02
Threat Entry Updated 2026-08-02

CVE-2026-16063 - Event Booking Manager For Woocommerce Plugin

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author role and above to inject arbitrary JavaScript that executes in the browser of any visitor viewing the event, including administrators.

PLUGIN Event Booking Manager For Woocommerce

CVE-2026-16063

UNKNOWN CVSS 0.0 2026-08-02
Threat Entry Updated 2026-08-02

CVE-2026-16062 - Event Booking Manager For Woocommerce Plugin

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 itself, but if one is present via another installed Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 or , this could lead to actions such as arbitrary file deletion, sensitive data retrieval, or remote code execution. This…

PLUGIN Event Booking Manager For Woocommerce

CVE-2026-16062

UNKNOWN CVSS 0.0 2026-08-02
Scroll to top