WordPress Plugin Vulnerabilities

Events Made Easy < 3.1.2 - Unauthenticated Payment Bypass

Description

The plugin does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a separate, higher-priced booking marked as fully paid.

Proof of Concept

Affects Plugins

Fixed in 3.1.2

References

Miscellaneous

Original Researcher
Haitam Lazaar
Submitter
Haitam Lazaar
Verified
Yes

Timeline

Publicly Published
2026-07-07 (about 1 month ago)
Added
2026-07-07 (about 1 month ago)
Last Updated
2026-07-07 (about 1 month ago)

Other