GHSA-2pgf-j495-ffj6MediumCVSS 4.9

The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who...

Published
September 17, 2026
Last Modified
September 17, 2026

🔗 CVE IDs covered (1)

📋 Description

The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.

🔗 References (3)