The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native… (CVE-2026-16067)
The Event Booking Manager for WooCommerce (Pro) WordPress plugin versions before 5.0.3 contains a vulnerability where the ticket price is not validated on the server during its native checkout process. This flaw allows unauthenticated users to supply arbitrary ticket prices, potentially booking paid event tickets for free and obtaining valid bookings without payment.
AI Analysis
Technical Summary
The vulnerability in the Event Booking Manager for WooCommerce (Pro) plugin prior to version 5.0.3 arises because the plugin does not re-derive the event's configured ticket price on the server side during its native (non-WooCommerce) checkout. Instead, it trusts the per-ticket price provided by the client. This lack of server-side validation enables unauthenticated attackers to manipulate ticket prices and complete bookings without paying, resulting in unauthorized free access to paid events.
Potential Impact
Unauthenticated attackers can exploit this vulnerability to obtain completed bookings and valid tickets for paid events at no cost. This leads to financial loss for event organizers and undermines the integrity of the ticketing system. There is no impact on confidentiality or availability reported.
Mitigation Recommendations
A fix is available in version 5.0.3 of the Event Booking Manager for WooCommerce (Pro) plugin. Users should upgrade to version 5.0.3 or later to ensure server-side validation of ticket prices during checkout. No other mitigation is indicated.
The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native… (CVE-2026-16067)
Description
The Event Booking Manager for WooCommerce (Pro) WordPress plugin versions before 5.0.3 contains a vulnerability where the ticket price is not validated on the server during its native checkout process. This flaw allows unauthenticated users to supply arbitrary ticket prices, potentially booking paid event tickets for free and obtaining valid bookings without payment.
CVSS v3.1
Score 5.3medium
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Event Booking Manager for WooCommerce (Pro) plugin prior to version 5.0.3 arises because the plugin does not re-derive the event's configured ticket price on the server side during its native (non-WooCommerce) checkout. Instead, it trusts the per-ticket price provided by the client. This lack of server-side validation enables unauthenticated attackers to manipulate ticket prices and complete bookings without paying, resulting in unauthorized free access to paid events.
Potential Impact
Unauthenticated attackers can exploit this vulnerability to obtain completed bookings and valid tickets for paid events at no cost. This leads to financial loss for event organizers and undermines the integrity of the ticketing system. There is no impact on confidentiality or availability reported.
Mitigation Recommendations
A fix is available in version 5.0.3 of the Event Booking Manager for WooCommerce (Pro) plugin. Users should upgrade to version 5.0.3 or later to ensure server-side validation of ticket prices during checkout. No other mitigation is indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-3qf4-97w4-w66g
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-16067"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a7573a5bf8831d539d92953
Added to database: 08/07/2026, 05:56:53 UTC
Last enriched: 08/14/2026, 13:03:27 UTC
Last updated: 09/21/2026, 22:01:32 UTC
Views: 40
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.