---
id: CVE-2026-16064
title: >-
  The Event Booking Manager for WooCommerce  WordPress plugin before 5.3.7 does
  not properly verify authorization on the object being modified when
  quick-editing events, only checking a global capability, allowing users with
  the Contributo…
summary: >-
  The Event Booking Manager for WooCommerce  WordPress plugin before 5.3.7 does
  not properly verify authorization on the object being modified when
  quick-editing events, only checking a global capability, allowing users with
  the Contributo…
severity: none
published: '2026-08-02'
updated: '2026-08-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16064'
references:
  - url: 'https://wpscan.com/vulnerability/881ba365-b2ce-41e1-92bb-e5fa275f8a06/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-08-02T13:18:29.290Z'
epss: 0.0023
epssPercentile: 0.12368
---

## Overview

The Event Booking Manager for WooCommerce  WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and pages on the site, including content they do not own.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
