CyberRota Analysis
AI-GeneratedThe Event Booking Manager for WooCommerce plugin in WordPress versions prior to 5.3.7 is vulnerable due to inadequate authorization checks during quick-editing of events, enabling users with Contributor roles and higher to alter titles and publication statuses of any posts and pages, including those they do not own. This could lead to unauthorized content manipulation and potential misinformation on the site. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and pages on the site, including content they do not own.