CVE-2026-91077: Event Booking Manager for WooCommerce 5.3.6 - 5.7.2 - Contributor+ Unpublished Event Disclosure via mpwem_load_event_list
The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level access and above can retrieve other authors' private, draft and trashed events, together with event detail the standard listing does not show them. This discloses private events and their content that WordPress withholds from users lacking the readprivateposts capability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Event Booking Manager for WooCommerceto a version that resolves this vulnerability.Fixed in 5.7.3
Event History
Frequently Asked Questions
Which users can exploit this issue?
An attacker needs an authenticated WordPress account with contributor-level access or higher. They can retrieve private, draft, and trashed events created by other authors.
Which plugin versions should be remediated?
Versions 5.3.6 through 5.7.2 are affected. Upgrade to version 5.7.3 or later.