Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vc5f-85m8-x67v

Опубликовано: 17 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.7

Описание

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom registration fields) by supplying an enumerable booking reference. Exploitation is limited to sites configured to use the Event Booking Manager for WooCommerce WordPress plugin before 5.3.8's native (non-WooCommerce) checkout, which is not the default.

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom registration fields) by supplying an enumerable booking reference. Exploitation is limited to sites configured to use the Event Booking Manager for WooCommerce WordPress plugin before 5.3.8's native (non-WooCommerce) checkout, which is not the default.

EPSS

Процентиль: 6%
0.00166
Низкий

3.7 Low

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 3.7
nvd
2 дня назад

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom registration fields) by supplying an enumerable booking reference. Exploitation is limited to sites configured to use the Event Booking Manager for WooCommerce WordPress plugin before 5.3.8's native (non-WooCommerce) checkout, which is not the default.

EPSS

Процентиль: 6%
0.00166
Низкий

3.7 Low

CVSS3

Дефекты

CWE-639