CVE · Medium

CVE-2026-15148 — WP Events Manager [wp-events-manager] < 2.2.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15148 WP Events Manager [wp-events-manager] < 2.2.5 Insufficient Verification of Data Authenticity Medium 5.3 < 2.2.5 2.2.5 2026-08-07

CVE-2026-15148

The WP Events Manager plugin for WordPress has a vulnerability that allows unauthorized users to mark any booking as paid without actually processing a payment. This occurs because the plugin does not properly verify the source of incoming payment notifications or ensure that the payment amount matches the booking total. As a result, an attacker can manipulate a booking's payment status without the merchant's account being charged, potentially affecting other users' bookings.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.