CVE-2026-15148
The WP Events Manager plugin for WordPress has a vulnerability that allows unauthorized users to mark any booking as paid without actually processing a payment. This occurs because the plugin does not properly verify the source of incoming payment notifications or ensure that the payment amount matches the booking total. As a result, an attacker can manipulate a booking's payment status without the merchant's account being charged, potentially affecting other users' bookings.
Based on public CVE data (MITRE/NVD).