Medium severity5.3NVD Advisory· Published Aug 6, 2026
CVE-2026-14842
CVE-2026-14842
Description
The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a separate, higher-priced booking marked as fully paid.
Affected products
1- Range: <3.1.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.