What is CVE-2026-14842?
CVE-2026-14842 affects The Events Made Easy WordPress plugin before version 3.1.2, which fails to bind the payment authorization token to the charged payment record. This allows unauthenticated attackers to pay a small amount for a cheap booking and fraudulently mark a separate, higher-priced booking as fully paid. Updating to version 3.1.2 or later is strongly recommended.
Azərbaycanca: CVE-2026-14842, Events Made Easy WordPress plugin-inin 3.1.2-dən əvvəlki versiyalarında ödəniş autorizasiyasının təsdiqlənməməsinə səbəb olan boşluqdur. Autentifikasiya olunmamış hücumçular ucuz bir sifariş üçün aşağı məbləğ ödəyərək daha bahalı sifarişi ödənilmiş kimi göstərə bilərlər. Plugin-i ən qısa zamanda 3.1.2 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which WordPress plugin is affected by CVE-2026-14842 and what is its root cause?
The vulnerability affects The Events Made Easy plugin before version 3.1.2. The root cause is that the payment authorization token is not bound to the charged payment record.
How can an unauthenticated attacker exploit CVE-2026-14842?
An attacker can pay a small amount for a cheap booking and fraudulently mark a separate, higher-priced booking as fully paid.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.