Executive brief
The Event Tickets Manager for WooCommerce plugin for WordPress, which is used to manage and sell event tickets online, contains a security flaw that allows unauthorized individuals to perform actions they should not have access to. An attacker could exploit this to modify ticket data or settings without needing to log in. This could lead to unauthorized changes in event management and potential disruption of ticket sales operations.
Technical details
The Event Tickets Manager for WooCommerce plugin for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862) in versions up to and including 1.5.3. This vulnerability allows an unauthenticated remote attacker to execute functions that should be restricted to higher-privileged users. The attack can be carried out over the network without any user interaction. While the CVSS score is 7.5 (High), the primary impact is on integrity, as attackers can modify data but not necessarily view sensitive information or crash the service. The issue is resolved in version 1.5.4.
Affected products
- MagePeople Event Tickets Manager for WooCommerce <= 1.5.3
Timeline
- 2026-01-31: disclosed: Reported by Nguyen Ba Khanh
- 2026-04-07: advisory: Patchstack advisory published
- 2026-04-07: patched: Fixed in version 1.5.4
- 2026-06-15: advisory: NVD published date