PT-2026-68648 · WordPress · Events Made Easy
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Events Made Easy WordPress plugin versions prior to 3.1.2
Description
An issue exists where the payment authorization token is not bound to the specific payment record being charged. This allows unauthenticated attackers to complete a payment for a low-cost booking and subsequently apply that authorization to mark a separate, higher-priced booking as fully paid.
Recommendations
Update the Events Made Easy WordPress plugin to version 3.1.2 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Events Made Easy