What is CVE-2026-14205?
This vulnerability exists in the WP Events Manager WordPress plugin before version 2.2.5, allowing any authenticated user to create a completed booking for a paid event without payment by manipulating the quantity parameter during registration. Updating the plugin to version 2.2.5 or later is required to fix the issue.
Azərbaycanca: Bu zəiflik WP Events Manager WordPress plaginində aşkarlanıb, 2.2.5-dən əvvəlki versiyaları təsir edir. İstənilən autentifikasiya olunmuş istifadəçi ödəniş tələb edən tədbirə qeydiyyatda quantity parametrini manipulyasiya edərək ödəniş etmədən tamamlanmış bron yarada bilir. Plaqini ən azı 2.2.5 versiyasına yeniləmək lazımdır.
FAQ2
Which versions of WP Events Manager plugin are affected by the booking without payment vulnerability?
This vulnerability affects the WP Events Manager plugin versions before 2.2.5.
How can a user exploit CVE-2026-14205 to register for a paid event?
Any authenticated user can create a completed booking for a paid event without payment by manipulating the quantity parameter during registration.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.