Executive brief
Event Booking Manager for WooCommerce is a WordPress plugin for managing event bookings and ticketing. The plugin fails to safely handle serialized data in event timeline and FAQ content fields, allowing contributors and higher-level users to inject malicious PHP objects. If another installed plugin or theme contains a suitable code gadget, attackers could delete files, access sensitive data, or execute arbitrary code on the website.
Technical details
The vulnerability is a PHP object injection (CWE-502) in the plugin's handling of event timeline "Day content" and FAQ answer fields. The plugin stores user input via unslash operations without preventing deserialization, and later deserializes this data in AJAX handlers (mep_change_date_status and get_mpwem_ticket) without specifying an allowed_classes restriction on unserialize(). Contributors and above can craft serialized PHP objects and plant them in draft events; the objects are later unserialized during AJAX requests, triggering __wakeup() and __destruct() magic methods. While the plugin itself contains no usable gadget chain, chaining with POP gadgets from other plugins or themes enables file operations, data theft, or RCE. The fix was incomplete; version 5.3.7 addresses this issue.
Affected products
- mage-eventpress Event Booking Manager for WooCommerce before 5.3.7
Timeline
- 2026-07-22: disclosed
- 2026-08-02: advisory: NVD published
- 2026-01-01: patched: Fix available in version 5.3.7