MEDIUM
Events Made Easy
CVE published 2026-08-06
CVE-2026-14842
The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a separate, higher-priced booking marked as fully paid. This vulnerability affects users of the plugin who handle payments, as it could lead to unauthorized payments and financial loss. The [truncated]