Executive brief
Event Tickets and Registration is a popular WordPress plugin for managing event bookings and payments. An unauthenticated attacker can bypass security controls on the Stripe payment integration endpoint, allowing them to overwrite the site's Stripe merchant credentials and redirect all customer payments to their own account—causing immediate financial loss and potential customer data exposure.
Technical details
The plugin contains a missing capability check on the Stripe OAuth return endpoint (REST_Return_Endpoint.php), allowing unauthenticated attackers to submit requests that overwrite Stripe merchant credentials including access tokens, publishable keys, and account ID. The vulnerability affects all versions up to and including 5.27.4. Attack preconditions are minimal—only network access to the WordPress site is required; no authentication or user interaction is needed. An attacker exploiting this flaw can fully compromise payment processing by routing transactions to their own Stripe account. A patch should be available in a version after 5.27.4.
Affected products
- The Events Calendar Event Tickets and Registration up to and including 5.27.4
Timeline
- 2026-09-08: disclosed