CyberRota Analysis
AI-GeneratedThe Events Made Easy WordPress plugin prior to version 3.1.2 is vulnerable due to its failure to associate the payment authorization token with the corresponding payment record. This flaw allows unauthenticated attackers to exploit the system by making low-cost payments while marking higher-priced bookings as fully paid, potentially leading to financial losses for businesses. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a separate, higher-priced booking marked as fully paid.