Threats Tagged 'cve-2026-16064'
View all threats tagged with 'cve-2026-16064'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-16064'
Click on any threat for detailed analysis and mitigation recommendations
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when… (CVE-2026-16064)CVE-2026-16064 0 The Event Booking Manager for WooCommerce WordPress plugin versions before 5.3.7 contains an authorization bypass vulnerability. This flaw allows users with the Contributor role and above to modify the title and publication status of posts and pages they do not own by exploiting improper authorization checks during quick-editing of events. Join the discussion | GCVE Database | 08/02/2026, 06:30:22 UTC Added: 08/02/2026, 21:27:12 UTC |
CVE-2026-16064: CWE-863 Incorrect Authorization in Event Booking Manager for WooCommerceCVE-2026-16064 0 The Event Booking Manager for WooCommerce WordPress plugin before version 5.3.7 contains an authorization vulnerability. It fails to properly verify user permissions when quick-editing events, relying only on a global capability check. This flaw allows users with the Contributor role or higher to modify the title and publication status of any posts or pages on the site, including those they do not own. Join the discussion | CVE Database V5 | 08/02/2026, 06:00:12 UTC Added: 08/02/2026, 19:26:02 UTC |
Showing 1 to 2 of 2 results