Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 08 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wp-eventmanager Wp-eventmanager wp Event Manager |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wp-eventmanager Wp-eventmanager wp Event Manager |
Fri, 07 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 CWE-703 |
Fri, 07 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 | |
| Metrics |
cvssV3_1
|
Fri, 07 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 CWE-703 |
Fri, 07 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment. | |
| Title | WP Events Manager < 2.2.5 - Subscriber+ Payment Bypass via 'qty' Parameter | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-07T18:01:41.454Z
Reserved: 2026-06-30T09:37:41.730Z
Link: CVE-2026-14205
Updated: 2026-08-07T18:01:37.078Z
Status : Received
Published: 2026-08-07T06:16:54.383
Modified: 2026-08-07T18:17:07.073
Link: CVE-2026-14205
No data.
OpenCVE Enrichment
Updated: 2026-08-08T20:53:39Z
-
CWE-287
Improper Authentication