GHSA-655w-h872-387jMediumCVSS 5.3
The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token...
🔗 CVE IDs covered (1)
📋 Description
The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a separate, higher-priced booking marked as fully paid.