WordPress Plugin Vulnerabilities

Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification via mpwem_quick_edit_event

Description

The plugin does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and pages on the site, including content they do not own.

Proof of Concept

Affects Plugins

Fixed in 5.3.7

References

Classification

Type
INCORRECT AUTHORISATION
CWE

Miscellaneous

Original Researcher
Yaswanth Reddy Sunkara
Submitter
Yaswanth Reddy Sunkara
Verified
Yes

Timeline

Publicly Published
2026-07-22 (about 11 days ago)
Added
2026-07-22 (about 10 days ago)
Last Updated
2026-07-22 (about 10 days ago)

Other