Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-91008

Опубликовано: 17 сент. 2026
Источник: nvd
CVSS3: 3.7
EPSS Низкий

Описание

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom registration fields) by supplying an enumerable booking reference. Exploitation is limited to sites configured to use the Event Booking Manager for WooCommerce WordPress plugin before 5.3.8's native (non-WooCommerce) checkout, which is not the default.

EPSS

Процентиль: 6%
0.00166
Низкий

3.7 Low

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 3.7
github
2 дня назад

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom registration fields) by supplying an enumerable booking reference. Exploitation is limited to sites configured to use the Event Booking Manager for WooCommerce WordPress plugin before 5.3.8's native (non-WooCommerce) checkout, which is not the default.

EPSS

Процентиль: 6%
0.00166
Низкий

3.7 Low

CVSS3

Дефекты

CWE-639