AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14205

CRITICAL · CVSS 9.8 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The WP Events Manager plugin for WordPress versions prior to 2.2.5 is vulnerable due to inadequate validation of the requested quantity during event registration, enabling authenticated users to manipulate the quantity and complete bookings for paid events without payment. This flaw poses a significant risk of financial loss for event organizers and could lead to unauthorized access to event resources. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-14205
Severity
CRITICAL
CVSS
9.8
EPSS
0.27%
WordPress

Original NVD Description

The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.