WordPress Plugin Vulnerabilities

WP Events Manager < 2.2.5 - Subscriber+ Payment Bypass via 'qty' Parameter

Description

The plugin does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.

Proof of Concept

Affects Plugins

Fixed in 2.2.5

References

Classification

Miscellaneous

Original Researcher
Mustafa Ahmed
Submitter
Mustafa Ahmed
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-08-03 (about 25 days ago)
Added
2026-08-03 (about 25 days ago)
Last Updated
2026-08-03 (about 25 days ago)

Other