Event Booking Manager for WooCommerce <= 5.7.5 - Unauthenticated Missing Authorization to Paid Event RSVP Registration and Online Event Details Disclosure
- ID
- WPSEC-2026-0471
- Plugin
- Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar (mage-eventpress)
- Affected
- from 5.3.6 before 5.7.6
- Remediation
- Update to 5.7.6 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
- Weakness
- CWE-862
- Usage
- Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-06
- Attack surface
- Event Booking Manager for WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized registration for paid events in versions 5.3.6 up to, and including, 5.7.5. This is due to the public RSVP submission AJAX handler not verifying that the submitted event ID belongs to an event in RSVP mode. This makes it possible for unauthenticated attackers, using the nonce printed on any public RSVP form, to record completed zero-price RSVP responses against paid ticketed events or other posts, and to have the event's booking confirmation email sent to an address of their choosing. For online events, this email includes the virtual event access details that the organizer intends only for ticket buyers. Exploitation requires the site to have at least one published RSVP event.
References
- https://wpsec.com/vuln/WPSEC-2026-0471/
- https://plugins.svn.wordpress.org/mage-eventpress/tags/5.7.6/
- https://wordpress.org/plugins/mage-eventpress/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS