Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-91008— Event Booking Manager for WooCommerce < 5.3.8 - Unauthenticated Attendee PII Disclosure via Booking Confirmation Panel

Quick assessment

Affected
Unknown Event Booking Manager for WooCommerce
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WooCommerce 事件预订管理器(Event Booking Manager for WooCommerce)WordPress 插件在 5.3.8 版本之前未对预订确认详情的渲染执行所有权或授权检查,使得未认证的攻击者能够通过提供可枚举的预订参考编号,获取已注册参与者的个人信息(包括全名、电子邮件地址、电话号码以及自定义注册字段)。该漏洞的利用仅限于那些配置为使用 5.3.8 之前版本的 Event Booking Manager for WooCommerce 插件原生(非 WooCommerce)结账流

AI Predicted 7.5 Difficulty: Easy
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-91008

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Event Booking Manager for WooCommerce < 5.3.8 - Unauthenticated Attendee PII Disclosure via Booking Confirmation Panel
Source: CVE Program / CVE List V5
Vulnerability Description
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom registration fields) by supplying an enumerable booking reference. Exploitation is limited to sites configured to use the Event Booking Manager for WooCommerce WordPress plugin before 5.3.8's native (non-WooCommerce) checkout, which is not the default.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Event Booking Manager for WooCommerce 5.3.6 ~ 5.3.8 -

II. Public POCs for CVE-2026-91008

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-91008

登录查看更多情报信息。

Vendor Advisories for CVE-2026-91008 (1)

Same Patch Batch · Unknown · 2026-09-17 · 29 CVEs total

CVE-2026-86801 8.8 HIGH To Do List Member 1.4 - 1.6 - Unauthenticated Stored XSS, File Listing and Deletion via Un
CVE-2026-87963 8.6 HIGH Yo 1.1 - 1.3.1 - Unauthenticated SQL Injection via username Parameter
CVE-2026-87829 4.3 MEDIUM Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Unvalidated
CVE-2026-87831 4.3 MEDIUM Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Customer Ad
CVE-2026-91017 3.7 LOW Robokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment Bypass via For
CVE-2025-15697 Dictionary <= 1.0 - Reflected XSS via Multiple Parameters
CVE-2026-85128 Choose User Role at Registration for WooCommerce < 1.3.3 - Unauthenticated Privilege Escal
CVE-2026-85130 WPLP Cookie Consent < 4.4.4 - Unauthenticated Stored XSS via Consent Logs
CVE-2026-86707 Private Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey' Parameter
CVE-2026-86709 The Pressengine <= 1.0 - Unauthenticated Authentication Bypass
CVE-2026-86710 Login with QR <= 1.0.0 - Unauthenticated Authentication Bypass via 'autologin_code' Parame
CVE-2026-86446 LearnPress 4.4.3 - 4.4.6 - Unauthenticated Quiz Answer Disclosure via check-answer REST En
CVE-2026-87836 Comments Import & Export 2.1.11 - 2.5.3 - Author+ Comment PII Disclosure via Export
CVE-2026-87786 Dewa Kirim <= 1.0.0 - Unauthenticated Stored XSS via Checkout Coordinates
CVE-2026-86824 Newsletter < 9.3.8 - Unauthenticated Subscriber PII Disclosure and Modification via Predic
CVE-2026-86788 HT Mega 3.2.0 - 3.2.5 - Contributor+ Stored XSS via Section Headline Tag
CVE-2026-90922 Paid Member Subscriptions < 3.0.9 - Unauthenticated Membership Payment Bypass via PayPal S
CVE-2026-88792 Dictionary <= 1.0 - Unauthenticated Stored XSS via Direct Dictionary Update
CVE-2026-88795 wpShopGermany IT-RECHT KANZLEI < 2.4 - Unauthenticated RCE via Predictable API Token
CVE-2026-88904 PuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privi

Showing top 20 of 29 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-91008

No comments yet


Leave a comment