Ticket Booking Vulnerability in Event Booking Manager for WooCommerce Plugin
CVE-2026-16067
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 August 2026
Badges
What is CVE-2026-16067?
The Event Booking Manager for WooCommerce (Pro) plugin versions prior to 5.0.3 inadequately validates ticket pricing during native checkout. Instead of re-confirming the configured ticket price on the server, it relies on the client-supplied price. This flaw permits unauthorized users to register for paid event tickets without payment, resulting in free access to otherwise chargeable events and compromising the integrity of bookings.
Affected Version(s)
Event Booking Manager for WooCommerce (Pro) 0 < 5.0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved