Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qf4-97w4-w66g

Опубликовано: 07 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re-deriving the event's configured price. This allows unauthenticated users to book paid event tickets for free, obtaining completed bookings and valid tickets at no cost.

The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re-deriving the event's configured price. This allows unauthenticated users to book paid event tickets for free, obtaining completed bookings and valid tickets at no cost.

EPSS

Процентиль: 14%
0.00236
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-472

Связанные уязвимости

CVSS3: 5.3
nvd
23 дня назад

The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re-deriving the event's configured price. This allows unauthenticated users to book paid event tickets for free, obtaining completed bookings and valid tickets at no cost.

EPSS

Процентиль: 14%
0.00236
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-472