CVE-2026-16067: Event Booking Manager for WooCommerce (Pro) < 5.0.3 - Unauthenticated Payment Bypass via Client-Controlled Ticket Price
The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re-deriving the event's configured price. This allows unauthenticated users to book paid event tickets for free, obtaining completed bookings and valid tickets at no cost.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: Event Booking Manager for WooCommerce (Pro)to a version that resolves this vulnerability.Fixed in 5.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16067?
The severity of CVE-2026-16067 is medium with a score of 5.3.
What does CVE-2026-16067 exploit?
CVE-2026-16067 exploits the lack of server-side validation of the ticket price in the Event Booking Manager for WooCommerce (Pro) plugin.
How do I fix CVE-2026-16067?
To fix CVE-2026-16067, update the Event Booking Manager for WooCommerce (Pro) plugin to version 5.0.3 or later.
Who is affected by CVE-2026-16067?
Users of the Event Booking Manager for WooCommerce (Pro) plugin prior to version 5.0.3 are affected by CVE-2026-16067.
What is the potential impact of CVE-2026-16067?
The potential impact of CVE-2026-16067 is unauthorized payment bypass during ticket purchasing.