What is CVE-2026-15148?
The WP Events Manager plugin for WordPress prior to version 2.2.5 fails to verify the origin of payment notifications or if the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid. Affected sites should update the plugin to the latest version immediately.
Azərbaycanca: WordPress WP Events Manager plagini 2.2.5 versiyasından əvvəlki versiyalarda ödəniş bildirişlərinin mənbəyini və ödənilən məbləğin sifariş cəminə uyğunluğunu yoxlamadığına görə autentifikasiya olunmamış istifadəçilər istənilən bronu ödənilmiş kimi işarələyə bilər. Təsirə məruz qalan saytlar dərhal plugini ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the WP Events Manager plugin are vulnerable to CVE-2026-15148?
All versions prior to 2.2.5 are vulnerable.
What can an unauthenticated attacker do by exploiting CVE-2026-15148?
The attacker can mark any booking as paid, as the plugin fails to verify the origin of payment notifications or if the paid amount matches the booking total.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.