Impact
The Events Made Easy WordPress plugin prior to version 3.1.2 does not bind the payment authorization token to the payment record that is being charged. Because of this oversight, an unauthenticated attacker can purchase a low‑cost booking and observe that a separate, higher‑priced booking is marked as fully paid, effectively allowing a payment bypass. The vulnerability permits an attacker to create a legitimate payment for one booking while granting a fully paid status to another transaction that the attacker never actually authorized, resulting in financial loss for the site owner.
Affected Systems
All installations of the Events Made Easy WordPress plugin with a version number lower than 3.1.2 are affected. The vendor is listed only as "Unknown:Events Made Easy" in the CNA data; no other affected products or versions are documented.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate severity. The EPSS score is not available and the vulnerability is not currently listed in the CISA KEV catalog. The most likely attack vector is via the plugin’s public booking and payment endpoints, where an unauthenticated user can submit payment requests. Because the flaw exists before token validation is linked to the record, an attacker who can perform unauthenticated payment requests can exploit it without any additional prerequisites.
OpenCVE Enrichment