The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the merchant, including other users' bookings.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 07 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-345 | |
| Metrics |
ssvc
|
Fri, 07 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wp-eventmanager Wp-eventmanager wp Event Manager |
|
| Weaknesses | CWE-284 CWE-639 |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wp-eventmanager Wp-eventmanager wp Event Manager |
Fri, 07 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the merchant, including other users' bookings. | |
| Title | WP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via IDOR | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-07T15:22:14.431Z
Reserved: 2026-07-08T19:33:59.091Z
Link: CVE-2026-15148
Updated: 2026-08-07T15:22:09.411Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T08:45:03Z