WordPress Plugin Vulnerabilities

Event Booking Manager for WooCommerce < 5.6.0 - Contributor+ Payment Gateway Credential Disclosure

Description

The plugin does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.

Proof of Concept

Affects Plugins

Fixed in 5.6.0

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Original Researcher
Artus KG
Submitter
Artus KG
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-09-15 (about 2 days ago)
Added
2026-09-15 (about 1 day ago)
Last Updated
2026-09-15 (about 1 day ago)

Other