WordPress Plugin Vulnerabilities
Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification via mpwem_quick_edit_event
Description
The plugin does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and pages on the site, including content they do not own.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
INCORRECT AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Yaswanth Reddy Sunkara
Submitter
Yaswanth Reddy Sunkara
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-22 (about 11 days ago)
Added
2026-07-22 (about 10 days ago)
Last Updated
2026-07-22 (about 10 days ago)