Executive brief
The Event Tickets and Registration plugin for WordPress, which manages event bookings and seating, contains a security flaw in how it handles seating assignments. An authorized user with basic 'contributor' permissions can modify or overwrite seating layouts, ticket inventories, and seat assignments for events they do not manage. This could lead to significant operational disruption, incorrect attendee data, and financial discrepancies for event organizers.
Technical details
The Event Tickets and Registration plugin (event-tickets) before version 5.29.0.1 fails to perform adequate authorization checks on specific seating-related actions. This vulnerability is classified as an Insecure Direct Object Reference (IDOR) (CWE-639). An authenticated attacker with at least Contributor-level privileges can exploit this flaw to overwrite seating layouts, ticket inventory counts, and attendee seat assignments for events they do not own. The attack is performed via network requests to vulnerable seating action endpoints. The issue is resolved in version 5.29.0.1.
Affected products
- The Events Calendar Event Tickets and Registration < 5.29.0.1
Timeline
- 2026-07-20: disclosed: Publicly published by WPScan
- 2026-08-01: advisory: CVE published to NVD dataset
- 2026-08-01: patched: Fixed in version 5.29.0.1