Sploitus

CVE-2026-15148

No indexed exploits for CVE-2026-15148 yet

The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the merchant, including other users' bookings.

Affected products
Events Manager
CVSS 3.1
5.3 MEDIUM
EPSS
0.1% (2th percentile)
Weakness
CWE-345
NVD status
Received
Published
2026-08-07
CVE-2026-15148 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-15148 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-15148 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.