What is CVE-2026-16064?
CVE-2026-16064 is an authorization bypass vulnerability in the Event Booking Manager for WooCommerce plugin before version 5.3.7. It allows users with Contributor-level permissions or above to modify event titles and publication statuses via quick-edit due to insufficient object-level access control. Updating to the patched version is strongly recommended.
Azərbaycanca: CVE-2026-16064, WooCommerce üçün Event Booking Manager plugininin 5.3.7-dən əvvəlki versiyalarında avtorizasiya yoxlanışı zəifliyidir. Bu boşluq Contributor və daha yüksək rol sahibi istifadəçilərə hadisə başlığını və nəşr statusunu dəyişməyə imkan verir. Pluginin ən son versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What versions of the Event Booking Manager plugin are affected by CVE-2026-16064?
CVE-2026-16064 affects versions of the Event Booking Manager for WooCommerce plugin prior to 5.3.7.
What can a Contributor-level user do by exploiting CVE-2026-16064?
CVE-2026-16064 allows users with Contributor-level permissions or above to modify event titles and publication statuses via quick-edit.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.