Junglewise Threat Intelligence

CVE-2026-16064: Event Booking Manager for WooCommerce authorization bypass in quick edit

CVE-2026-16064 · Severity: medium · CVSS 5.4 · Published 2026-08-02

Technologies: Mage Event Booking Manager for WooCommerce.

Executive brief

Event Booking Manager for WooCommerce is a WordPress plugin that allows site administrators to create and manage event listings alongside their WooCommerce store. A flaw in the plugin's authorization checks allows users with Contributor privileges to modify the title and publication status of any post or page on the site—including content they do not own—through the quick-edit event function. This could enable unauthorized users to unpublish critical pages, alter content, or manipulate the site's visibility in ways that disrupt business operations.

Technical details

The vulnerability is an authorization bypass (CWE-863) in the mpwem_quick_edit_event AJAX action. The plugin fails to verify that the user owns or has permission to modify the specific post being edited; instead, it only checks a global capability (edit_posts), which is granted to Contributor and higher roles. An authenticated Contributor can craft a direct AJAX request to /wp-admin/admin-ajax.php with an arbitrary post ID and desired post_title and post_status values to modify any post or page. No CSRF protection or nonce verification on the target post is performed. The fix is available in version 5.3.7 and later.

Affected products

  • mage Event Booking Manager for WooCommerce before 5.3.7

Timeline

  • 2026-07-22: disclosed
  • 2026-08-02: patched: Version 5.3.7 released

References