Executive brief
Events Booking is a popular Joomla extension used by websites to manage event registrations and process payments. A security flaw in this extension allows unauthorized individuals to discover the usernames and email addresses of registered users. This information could be used by malicious actors to conduct targeted phishing attacks or attempt unauthorized access to user accounts.
Technical details
The Events Booking extension for Joomla (versions 1.0 through 5.8.0) contains a user enumeration vulnerability. An unauthenticated remote attacker can exploit this flaw to programmatically retrieve sensitive account details, specifically usernames and email addresses, from the system. The vulnerability likely stems from improper access controls or verbose responses in the extension's registration or registrant management components. This data exposure facilitates credential stuffing and targeted social engineering. Users should update to a version beyond 5.8.0 if available, as the vendor released version 5.8.0 around the time of discovery.
Affected products
- joomdonation.com Events Booking extension for Joomla 1.0-5.8.0
Timeline
- 2026-07-15: patched: Version 5.8.0 released by vendor
- 2026-07-17: disclosed: CVE published to NVD