AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-14842

MEDIUM · CVSS 5.3 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Events Made Easy WordPress plugin prior to version 3.1.2 is vulnerable due to its failure to associate the payment authorization token with the corresponding payment record. This flaw allows unauthenticated attackers to exploit the system by making low-cost payments while marking higher-priced bookings as fully paid, potentially leading to financial losses for businesses. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-14842
Severity
MEDIUM
CVSS
5.3
EPSS
0.29%
WordPress

Original NVD Description

The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a separate, higher-priced booking marked as fully paid.