The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the merchant, including other users' bookings.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-07 08:16
Updated : 2026-08-26 16:31
NVD link : CVE-2026-15148
Mitre link : CVE-2026-15148
CVE.ORG link : CVE-2026-15148
JSON object : View
Products Affected
No product.
CWE
CWE-345
Insufficient Verification of Data Authenticity
