CVE-2026-91019

The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.

  • Published Sep 17, 2026
  • CVSS 4.9 medium
  • 0.4% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-91019 at the National Vulnerability Database