What the vulnerability does
01Description
The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re-deriving the event's configured price. This allows unauthenticated users to book paid event tickets for free, obtaining completed bookings and valid tickets at no cost.
Explanation of Vulnerability in Simple Terms
02Summary
Event Booking Manager for WooCommerce Pro versions before 5.0.3 contain an integrity vulnerability accessible over the network without authentication or user interaction. An attacker can modify data or content on the site. The vulnerability has a CVSS score of 5.3 (medium severity). Update to version 5.0.3 or later to resolve this issue.
What an attacker can do
03Attacker Capabilities
Modify or corrupt booking data and site content without logging in.
Potential impact on your site
04Site Impact
Attackers can alter booking records, event details, or other site data without your knowledge or permission.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
August 6, 2026
CVE published