CVE

CVE-2026-14205 — WP Events Manager [wp-events-manager] < 2.2.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-14205 WP Events Manager [wp-events-manager] < 2.2.5 Improper Authentication Unknown < 2.2.5 2.2.5 2026-08-07

CVE-2026-14205

The WP Events Manager WordPress plugin has a vulnerability in its payment processing for paid events. When a user registers for a paid event, the plugin doesn't properly check the quantity being requested, allowing an attacker to manipulate the price calculation. As a result, any authenticated user can book a paid event without actually paying for it.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.