PoC Index

CVE-2026-15148

MEDIUM 5.3EPSS 0.1%

The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the merchant, including other users' bookings.

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
0.11% chance of exploitation in the next 30 days, 2th percentile
Published
2026-08-07

Proof-of-concept exploits (1)

References

Related