Executive brief
The Event Booking Manager for WooCommerce plugin fails to restrict access to stored payment gateway credentials. Any WordPress user with Contributor-level access or higher can view and exfiltrate sensitive PayPal and Stripe API keys, including secret keys used to process transactions. This exposure allows account takeover and unauthorized transaction processing on behalf of the affected business.
Technical details
The vulnerability is a broken access control (CWE-284) flaw in the plugin's payment gateway configuration interface. The affected component fails to enforce proper authorization checks when retrieving stored credentials for PayPal and Stripe. An authenticated attacker with Contributor or higher role (a low privilege level in WordPress) can make requests to view or export the stored payment gateway configuration, which includes plaintext secret API keys. No network-level authentication bypass is required—exploitation requires only valid WordPress account credentials at a low privilege level. The vendor patched this in version 5.6.0 by implementing proper role-based access controls.
Affected products
- mage Event Booking Manager for WooCommerce before 5.6.0
Timeline
- 2026-09-15: disclosed
- 2026-09-17: patched: Version 5.6.0 released