CVE-2026-14842 UNKNOWN

CVE-2026-14842

Published: 2026-08-06

Description

The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a separate, higher-priced booking marked as fully paid.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…