The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.
https://wpscan.com/vulnerability/549c3611-934d-4712-83aa-cfe501647e80/