โ† Back to Dashboard

CVE-2026-14205

CRITICAL NVD
CVSS Score
9.8
Severity
CRITICAL
Source
NVD
Published
Aug 07, 2026
Description

The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.

View Full Details โ† Back