CyberRota Analysis
AI-GeneratedThe WP Events Manager plugin for WordPress versions prior to 2.2.5 is vulnerable due to inadequate validation of the requested quantity during event registration, enabling authenticated users to manipulate the quantity and complete bookings for paid events without payment. This flaw poses a significant risk of financial loss for event organizers and could lead to unauthorized access to event resources. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.