Impact
The WP Events Manager plugin before version 2.2.5 fails to verify that a payment notification originates from the correct merchant account and does not confirm that the payment amount matches the booking total. This flaw allows any unauthenticated user to submit a payment notification and mark any booking, including those belonging to other users, as paid. The consequence is a financial fraud scenario in which the system believes a legitimate transaction has taken place when none has, potentially leading to unauthorized use of paid events or services.
Affected Systems
WordPress sites that have the WP Events Manager plugin installed at a version older than 2.2.5. No other products or vendors are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not provided, so the likelihood of exploitation cannot be quantified, but the flaw is remotely exploitable without authentication. An attacker can craft an HTTP request to the payment notification endpoint, bypass the merchant and amount checks, and update the booking status. The vulnerability is not currently listed in CISA's KEV catalog, suggesting no publicly known exploits at present. However, the ability to tamper with booking records without credentials represents a significant business risk.
OpenCVE Enrichment