medium · CVSS v3 4.9
CVE-2026-91019
The Event Booking Manager for WooCommerce plugin (versions prior to 5.6.0) allows any WordPress user with Contributor-level access or higher
Overview
The Event Booking Manager for WooCommerce plugin (versions prior to 5.6.0) allows any WordPress user with Contributor-level access or higher to view stored PayPal and Stripe credentials, including secret keys. This flaw exposes sensitive payment configuration data to non‑admin users.
Description
The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.
Impact
Confidentiality: Payment gateway credentials (API keys, secrets) are exposed to users who should not have access, enabling potential unauthorized use of the merchant’s PayPal or Stripe accounts. Integrity: While the flaw does not directly alter configuration, exposed credentials could be used to modify payment settings or initiate fraudulent transactions. Availability: No direct impact.
Remediation
['Upgrade the Event Booking Manager plugin to version 5.6.0 or later, where access controls on payment configuration views have been added.', 'If an upgrade is not immediately possible, remove or downgrade Contributor and higher roles from the ability to view plugin settings, or disable the plugin’s payment configuration pages for those roles.', 'Rotate all exposed PayPal and Stripe API keys and secrets immediately after detecting the vulnerability.', 'Audit user roles and permissions to ensure least privilege for all WordPress users.']
Risk context
The CVSS v3 score of 4.9 classifies this issue as medium severity. Although no EPSS data is available, the exposure of payment credentials poses a tangible financial risk, warranting prompt remediation.
Affected products
- Event Booking Manager for WooCommerce
- WooCommerce
- WordPress
- PayPal
- Stripe
Scores
- Severity
- medium
- CVSS v2
- 4
- CVSS v3
- 4.9
- CVSS v4
- —
- EPSS
- —