Impact
The WP Events Manager WordPress plugin before version 2.2.5 lacks validation on the quantity parameter used when registering for a paid event, causing the price to be computed from an attacker‑controlled quantity. This flaw allows any authenticated user to create a completed booking for a paid event without actually paying, resulting in a payment processing bypass and potential revenue loss for site owners. The weakness is a form of improper authorization, allowing an authenticated user to perform actions beyond their intended privileges.
Affected Systems
The vulnerability affects installations of the WP Events Manager plugin older than 2.2.5 on any WordPress site. All users of the plugin before this release are at risk, regardless of site size or hosting environment. An upgrade to version 2.2.5 or newer resolves the issue.
Risk and Exploitability
The attack can be carried out by any authenticated user by supplying a crafted quantity value in the booking request, which the plugin accepts without validation. While the exploit does not provide remote code execution, it enables unauthorized financial transactions that can undermine the integrity of the event booking system. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the absence of a payment requirement makes the exploitation straightforward for privileged users, warranting prompt remediation.
OpenCVE Enrichment