CVE-2026-91077 PUBLISHED

Event Booking Manager for WooCommerce 5.3.6 - 5.7.2 - Contributor+ Unpublished Event Disclosure via mpwem_load_event_list

Assigner: WPScan
Reserved: 14.09.2026 Published: 23.09.2026 Updated: 23.09.2026

The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level access and above can retrieve other authors' private, draft and trashed events, together with event detail the standard listing does not show them. This discloses private events and their content that WordPress withholds from users lacking the read_private_posts capability.

Product Status

Vendor Unknown
Product Event Booking Manager for WooCommerce
Versions Default: unaffected
  • affected from 5.3.6 to 5.7.3 (excl.)

Credits

  • Artus KG finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE