The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the merchant, including other users' bookings.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-345 | |
| Metrics |
ssvc
|
Fri, 07 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wp-eventmanager Wp-eventmanager wp Event Manager |
|
| Weaknesses | CWE-284 CWE-639 |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wp-eventmanager Wp-eventmanager wp Event Manager |
Fri, 07 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the merchant, including other users' bookings. | |
| Title | WP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via IDOR | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-07T15:22:14.431Z
Reserved: 2026-07-08T19:33:59.091Z
Link: CVE-2026-15148
Updated: 2026-08-07T15:22:09.411Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T18:00:04Z