Description
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.
Published: 2026-08-07
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Events Manager WordPress plugin before version 2.2.5 lacks validation on the quantity parameter used when registering for a paid event, causing the price to be computed from an attacker‑controlled quantity. This flaw allows any authenticated user to create a completed booking for a paid event without actually paying, resulting in a payment processing bypass and potential revenue loss for site owners. The weakness is a form of improper authorization, allowing an authenticated user to perform actions beyond their intended privileges.

Affected Systems

The vulnerability affects installations of the WP Events Manager plugin older than 2.2.5 on any WordPress site. All users of the plugin before this release are at risk, regardless of site size or hosting environment. An upgrade to version 2.2.5 or newer resolves the issue.

Risk and Exploitability

The attack can be carried out by any authenticated user by supplying a crafted quantity value in the booking request, which the plugin accepts without validation. While the exploit does not provide remote code execution, it enables unauthorized financial transactions that can undermine the integrity of the event booking system. The CVSS score is 9.8, and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog, but the lack of a payment requirement makes the exploitation straightforward for privileged users, warranting prompt remediation.

Generated by OpenCVE AI on August 7, 2026 at 21:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Events Manager to version 2.2.5 or later, which addresses the Weak Authentication (CWE-287) weakness.
  • Enable automatic plugin updates or monitor the plugin’s release feed to apply future security fixes promptly, ensuring that any patches addressing these CWE weaknesses are quickly deployed.
  • If an immediate upgrade is not feasible, temporarily disable payment processing or limit booking capabilities for non‑trusted user roles until the patch is applied.

Generated by OpenCVE AI on August 7, 2026 at 21:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp-eventmanager
Wp-eventmanager wp Event Manager
Vendors & Products Wordpress
Wordpress wordpress
Wp-eventmanager
Wp-eventmanager wp Event Manager

Fri, 07 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-703

Fri, 07 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-703

Fri, 07 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.
Title WP Events Manager < 2.2.5 - Subscriber+ Payment Bypass via 'qty' Parameter
References

Subscriptions

Wordpress Wordpress
Wp-eventmanager Wp Event Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-07T18:01:41.454Z

Reserved: 2026-06-30T09:37:41.730Z

Link: CVE-2026-14205

cve-icon Vulnrichment

Updated: 2026-08-07T18:01:37.078Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T06:16:54.383

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-14205

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:53:39Z

Weaknesses