CVE-2026-14842

Summary

The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a separate, higher-priced booking marked as fully paid.

Affected Software

VendorProductVersion RangeStatus
UnknownEvents Made Easy0 < 3.1.2affected

Weaknesses

  • CWE-639 Authorization Bypass Through User-Controlled Key

References