What is CVE-2026-16063?
This vulnerability exists in the "Event Booking Manager for WooCommerce" WordPress plugin before version 5.3.7. Users with the Author role and above can inject arbitrary JavaScript via unsanitized event timeline content, leading to a stored Cross-Site Scripting attack. Updating the plugin to version 5.3.7 or later is required to fix the issue.
Azərbaycanca: Bu boşluq "Event Booking Manager for WooCommerce" WordPress plaginində aşkar edilib. 5.3.7 versiyasından əvvəlki versiyalarda, Author roluna malik istifadəçilər hadisə zaman qrafiki məzmununa saflaşdırılmamış JavaScript kodu daxil edərək saxlanmış XSS hücumu həyata keçirə bilərlər. Plagini dərhal 5.3.7 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What user role is required to exploit CVE-2026-16063?
At minimum, the Author role is required to exploit this vulnerability.
What action is required to fix CVE-2026-16063?
The plugin must be updated to version 5.3.7 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.