What is CVE-2026-16067?
CVE-2026-16067 is a vulnerability in the Event Booking Manager for WooCommerce (Pro) WordPress plugin where the server does not validate the ticket price during native checkout, trusting client-supplied values. This allows unauthenticated attackers to manipulate the price paid for event tickets. Affected versions before 5.0.3 must be updated immediately.
Azərbaycanca: CVE-2026-16067 Event Booking Manager for WooCommerce (Pro) WordPress plaginində server tərəfində bilet qiymətlərinin yoxlanılmaması zəifliyidir. Bu, autentifikasiya olunmamış istifadəçilərə checkout prosesində müştəri tərəfindən göndərilən qiyməti manipulyasiya edərək ödəniş məbləğini azaltmağa imkan verir. Plaginin 5.0.3-dən əvvəlki versiyaları risk altındadır, dərhal yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which versions of the Event Booking Manager for WooCommerce plugin are affected by CVE-2026-16067?
This vulnerability affects plugin versions before 5.0.3.
How can an attacker manipulate the payment amount using CVE-2026-16067?
Unauthenticated attackers can reduce the payment amount by manipulating the client-supplied ticket price during the checkout process, due to the server not validating the ticket price on the server side.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.