CVE-2026-8608: CWE-345 Insufficient Verification of Data Authenticity in awordpresslife Event Monster – Event Manager, Ticket Booking & Registration
The Event Monster plugin for WordPress up to version 2.1.0 has a vulnerability where it insufficiently verifies payment data authenticity. The AJAX handler capture_payment() accepts client-supplied payment details without server-side verification or proper authorization checks. This allows unauthenticated attackers to forge payment records, mark bookings as completed, and receive valid confirmation emails with QR code tickets without paying.
AI Analysis
Technical Summary
CVE-2026-8608 describes an insufficient verification of data authenticity vulnerability (CWE-345) in the Event Monster – Event Manager, Ticket Booking & Registration WordPress plugin versions up to and including 2.1.0. The vulnerability arises because the capture_payment() AJAX handler (registered via wp_ajax_nopriv_em_capture_payment) trusts client-supplied payment data such as transaction ID, amount, and payment status without verifying these details against the PayPal API or any other payment gateway. Additionally, the handler lacks nonce or capability checks, enabling unauthenticated attackers to forge payment records, mark bookings as completed, and obtain confirmation emails with valid QR code tickets without making actual payments.
Potential Impact
An attacker can exploit this vulnerability to bypass payment verification, resulting in forged payment records and unauthorized completion of bookings. This leads to issuance of valid confirmation emails and QR code tickets without any actual payment, causing potential revenue loss and fraudulent access to events.
Mitigation Recommendations
No official patch or remediation is currently available for this vulnerability. Users should monitor the vendor's advisory for updates. Until a fix is released, consider disabling or restricting access to the vulnerable AJAX handler to prevent exploitation.
CVE-2026-8608: CWE-345 Insufficient Verification of Data Authenticity in awordpresslife Event Monster – Event Manager, Ticket Booking & Registration
Description
The Event Monster plugin for WordPress up to version 2.1.0 has a vulnerability where it insufficiently verifies payment data authenticity. The AJAX handler capture_payment() accepts client-supplied payment details without server-side verification or proper authorization checks. This allows unauthenticated attackers to forge payment records, mark bookings as completed, and receive valid confirmation emails with QR code tickets without paying.
CVSS v3.1
Score 5.3medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-8608 describes an insufficient verification of data authenticity vulnerability (CWE-345) in the Event Monster – Event Manager, Ticket Booking & Registration WordPress plugin versions up to and including 2.1.0. The vulnerability arises because the capture_payment() AJAX handler (registered via wp_ajax_nopriv_em_capture_payment) trusts client-supplied payment data such as transaction ID, amount, and payment status without verifying these details against the PayPal API or any other payment gateway. Additionally, the handler lacks nonce or capability checks, enabling unauthenticated attackers to forge payment records, mark bookings as completed, and obtain confirmation emails with valid QR code tickets without making actual payments.
Potential Impact
An attacker can exploit this vulnerability to bypass payment verification, resulting in forged payment records and unauthorized completion of bookings. This leads to issuance of valid confirmation emails and QR code tickets without any actual payment, causing potential revenue loss and fraudulent access to events.
Mitigation Recommendations
No official patch or remediation is currently available for this vulnerability. Users should monitor the vendor's advisory for updates. Until a fix is released, consider disabling or restricting access to the vulnerable AJAX handler to prevent exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-05-14T15:59:18.646Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a236054e29bf47b50d6f298
Added to database: 06/05/2026, 23:48:36 UTC
Last enriched: 06/13/2026, 09:56:46 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 90
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.