Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-14205: WP Events Manager Paid Events Can Be Bypassed by Malicious Users
CVE-2026-14205
CVE-2026-14205
Summary
WP Events Manager, a popular WordPress plugin, has a security issue that allows any authenticated user to book paid events without paying. This can lead to financial losses for event organizers. To fix this, update the plugin to version 2.2.5 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | wp events manager | < 2.2.5 |
Original title
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing...
Original description
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.
Vulnerability type
CWE-287
Improper Authentication
Published: 7 Aug 2026 · Updated: 7 Aug 2026 · First seen: 7 Aug 2026