CVE-2026-15148
The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the merchant, including other users' bookings.
- Affected products
- Events Manager
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 0.1% (2th percentile)
- Weakness
- CWE-345
- NVD status
- Received
- Published
- 2026-08-07
CVE-2026-15148 at NVD
No indexed exploits for CVE-2026-15148 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-15148 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.