Description
The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the merchant, including other users' bookings.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 07 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wp-eventmanager Wp-eventmanager wp Event Manager |
|
| Weaknesses | CWE-284 CWE-639 |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wp-eventmanager Wp-eventmanager wp Event Manager |
Fri, 07 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the merchant, including other users' bookings. | |
| Title | WP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via IDOR | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-07T15:22:14.431Z
Reserved: 2026-07-08T19:33:59.091Z
Link: CVE-2026-15148
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T08:45:03Z