PT-2026-68875 · WordPress · Events Manager
CVE-2026-15148
·
Published
2026-08-07
·
Updated
2026-08-07
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP Events Manager versions prior to 2.2.5
Description
The plugin fails to verify if incoming payment notifications originate from the configured merchant account and does not check if the paid amount matches the booking total. This allows unauthenticated users to mark any booking, including those belonging to other users, as paid without a legitimate transaction occurring.
Recommendations
Update to version 2.2.5 or later.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Events Manager