Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-16067

Опубликовано: 06 авг. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re-deriving the event's configured price. This allows unauthenticated users to book paid event tickets for free, obtaining completed bookings and valid tickets at no cost.

EPSS

Процентиль: 14%
0.00236
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-472

Связанные уязвимости

CVSS3: 5.3
github
23 дня назад

The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re-deriving the event's configured price. This allows unauthenticated users to book paid event tickets for free, obtaining completed bookings and valid tickets at no cost.

EPSS

Процентиль: 14%
0.00236
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-472