WooCommerce 插件中的 Event Booking Manager 版本低于 5.7.3 时,其事件列表查询未限制为仅请求用户有权读取的事件。因此,具有贡献者级别访问权限及以上的用户可以检索到其他作者的个人私有事件、草稿事件和已删除事件,同时还可以看到标准列表中不显示的事件详情。这会导致隐私信息泄露,暴露出 WordPress 本应对其不具备 权限的用户隐藏的个人私有事件及其内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Event Booking Manager for WooCommerce | 5.3.6< 5.7.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Event Booking Manager for WooCommerce | 5.3.6 ~ 5.7.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86601 | 6.5 MEDIUM | WP Recipe Maker < 10.8.2 - Unauthenticated Arbitrary Shortcode Execution via Comment Conte |
| CVE-2026-86612 | 5.6 MEDIUM | Ninja Tables < 5.2.17 - Unauthenticated Arbitrary Shortcode Execution via Fluent Forms Dat |
| CVE-2026-84091 | 5.3 MEDIUM | SUMIT Payment Gateway for WooCommerce < 4.0.0 - Unauthenticated Payment Confirmation Forge |
| CVE-2026-90950 | 5.3 MEDIUM | Paid Member Subscriptions < 3.1.0 - Unauthenticated reCAPTCHA Bypass via Registration Form |
| CVE-2026-87978 | 5.3 MEDIUM | Paymob for WooCommerce < 4.1.14 - Unauthenticated Payment Bypass via Unverified Subscripti |
| CVE-2026-87071 | 5.3 MEDIUM | Forminator Forms < 1.57.2.1 - Unauthenticated Post Meta Injection on Submitted Posts |
| CVE-2026-87070 | 5.3 MEDIUM | Forminator Forms < 1.57.2.1 - Unauthenticated Poll Vote Limit Bypass via IP Spoofing |
| CVE-2026-86604 | 4.8 MEDIUM | GTranslate < 5.0.1 - Unauthenticated Arbitrary Shortcode Execution via Email Translation |
| CVE-2026-87848 | 3.7 LOW | MPCX Lightbox 1.2.2 - 1.2.5 - Unauthenticated Non-Public Post Content Disclosure |
| CVE-2026-93511 | Premium Packages < 7.2.1 - Unauthenticated PayPal Webhook Signature Verification Bypass | |
| CVE-2026-86842 | Real3D Flipbook Lite < 5.4 - Author+ Content Deletion and Stored XSS via Global Settings O | |
| CVE-2026-91024 | Booking Manager < 2.1.21 - Author+ SQLi via ICS Import Feed UID (sync_gid) | |
| CVE-2026-89331 | FluentBoards 1.95 - 2.0.15 - Unauthenticated Board Member Email Address Disclosure via Pub | |
| CVE-2026-88997 | JSM Show Post Metadata < 4.9.1 - Contributor+ Stored XSS via Custom Field Meta Key | |
| CVE-2026-87981 | Paymob for WooCommerce < 4.1.14 - Contributor+ Payment Gateway Configuration Deletion and | |
| CVE-2026-87074 | Forminator Forms < 1.57.2.1 - Unauthenticated Arbitrary Recipient Email Sending with Attac | |
| CVE-2026-87979 | Paymob for WooCommerce < 4.1.14 - Unauthenticated Saved Card Token Write to Any User via W | |
| CVE-2026-88929 | Sale Booster 7.0.0 - 7.5.1 - Unauthenticated Non-Public Product Disclosure | |
| CVE-2026-87069 | Forminator Forms < 1.57.2.1 - Subscriber+ Form Stripe Field Migration via migrate_stripe | |
| CVE-2026-86783 | PostX < 5.0.41 - Unauthenticated Custom Field Key Disclosure via REST API |
Showing top 20 of 57 CVEs. View all on vendor page → →
No comments yet