Executive brief
The Event Booking Manager for WooCommerce is a WordPress plugin used to manage event registrations and attendee bookings. The plugin contains an authorization flaw that allows unauthenticated attackers to retrieve sensitive attendee personal information (names, email addresses, phone numbers, and custom fields) by guessing or enumerating booking reference numbers. This exposure is limited to sites using the plugin's custom checkout process rather than the standard WooCommerce checkout.
Technical details
This is an Insecure Direct Object Reference (IDOR) vulnerability in the booking confirmation panel. The plugin fails to verify ownership or authorization before rendering booking details, allowing an unauthenticated attacker to access PII by supplying an enumerable booking reference parameter. The vulnerability is a broken access control issue (CWE-639) that requires no authentication and can be exploited via simple HTTP requests to the confirmation endpoint. Exploitation is practical only on sites configured to use the plugin's native checkout instead of WooCommerce's standard checkout (non-default configuration). The vulnerability is fixed in version 5.3.8 and later.
Affected products
- mage-eventpress Event Booking Manager for WooCommerce before 5.3.8
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Version 5.3.8 released