Event Booking Manager for WooCommerce <= 5.7.5 - Unauthenticated Missing Authorization to Paid Event RSVP Registration and Online Event Details Disclosure

Medium 4.8 CWE-862Fixed in 5.7.6
ID
WPSEC-2026-0471
Plugin
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar (mage-eventpress)
Affected
from 5.3.6 before 5.7.6
Remediation
Update to 5.7.6 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness
CWE-862
Usage
Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-06
Attack surface
Event Booking Manager for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized registration for paid events in versions 5.3.6 up to, and including, 5.7.5. This is due to the public RSVP submission AJAX handler not verifying that the submitted event ID belongs to an event in RSVP mode. This makes it possible for unauthenticated attackers, using the nonce printed on any public RSVP form, to record completed zero-price RSVP responses against paid ticketed events or other posts, and to have the event's booking confirmation email sent to an address of their choosing. For online events, this email includes the virtual event access details that the organizer intends only for ticket buyers. Exploitation requires the site to have at least one published RSVP event.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0