PT-2026-47070 · WordPress · Event Monster
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress versions prior to 2.1.1
Description
The software is affected by Insufficient Verification of Data Authenticity. The
capture payment() AJAX handler, registered via 'wp ajax nopriv em capture payment', trusts payment data provided by the client—specifically the transaction ID, amount, and payment status—without performing server-side verification against the PayPal API or other payment gateways. Additionally, the handler lacks nonce or capability checks. This allows unauthenticated attackers to forge payment records, mark bookings as Completed, and receive confirmation emails with valid QR code tickets without completing a payment.Recommendations
Update the plugin to a version later than 2.1.0.
As a temporary workaround, restrict access to the 'wp ajax nopriv em capture payment' AJAX handler to minimize the risk of exploitation.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Event Monster