๐Ÿ” CVE Alert

CVE-2026-15148

MEDIUM 5.3

WP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via IDOR

CVSS Score
5.3
EPSS Score
0.1%
EPSS Percentile
2th

The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the merchant, including other users' bookings.

Vendor unknown
Product wp events manager
Published Aug 7, 2026
Last Updated Aug 7, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wp events manager

Be the first to know when new medium vulnerabilities affecting unknown wp events manager are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / WP Events Manager
0 < 2.2.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/08d4761f-ddc6-48f4-909e-db38438e385e/

Credits

Muni Nitish Kumar Yaddala WPScan