What is CVE-2026-17166?
CVE-2026-17166 is an authorization bypass vulnerability in the 'Event Booking Manager for WooCommerce' WordPress plugin. Affecting all versions up to and including 5.3.7, this flaw allows unauthorized users to perform certain actions due to improper verification of user permissions. Site owners using this plugin should immediately apply the security update.
Azərbaycanca: CVE-2026-17166 WordPress üçün 'Event Booking Manager for WooCommerce' plaginində müəyyən edilmiş authorization bypass zəifliyidir. 5.3.7 versiyasına qədər təsir edən bu boşluq, plaginin istifadəçi icazələrini düzgün yoxlamaması səbəbindən imtiyazsız şəxslərə müəyyən əməliyyatlar icra etməyə imkan verir. Bu plaginin hər hansı versiyasını istifadə edən sayt sahibləri təhlükəsizlik yeniləməsini dərhal tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which WordPress plugin is affected by the CVE-2026-17166 vulnerability?
The 'Event Booking Manager for WooCommerce' plugin.
What should site owners do to protect against the CVE-2026-17166 vulnerability?
Immediately apply the security update.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.