The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level access and above can retrieve other authors' private, draft and trashed events, together with event detail the standard listing does not show them. This discloses private events and their content that WordPress withholds from users lacking the read_private_posts capability.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level access and above can retrieve other authors' private, draft and trashed events, together with event detail the standard listing does not show them. This discloses private events and their content that WordPress withholds from users lacking the read_private_posts capability.
Title Event Booking Manager for WooCommerce 5.3.6 - 5.7.2 - Contributor+ Unpublished Event Disclosure via mpwem_load_event_list
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T10:51:44.170Z

Reserved: 2026-09-14T17:24:31.808Z

Link: CVE-2026-91077

cve-icon Vulnrichment

Updated: 2026-09-23T10:33:02.416Z

cve-icon NVD

Status : Received

Published: 2026-09-23T06:17:05.737

Modified: 2026-09-23T11:17:17.653

Link: CVE-2026-91077

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses