CVE-2026-91019 UNKNOWN

CVE-2026-91019

Published: 2026-09-17

Description

The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…