Executive brief
The Event Tickets plugin for WordPress, used to manage event registrations and ticketing, contains a security flaw that allows unauthorized users to bypass certain restrictions. This could allow an attacker to perform actions or access features that should be restricted to authorized administrators or ticket holders. Exploitation of this vulnerability could lead to unauthorized changes to event data or disruption of ticketing operations.
Technical details
The Event Tickets plugin for WordPress is vulnerable to an authentication bypass by spoofing (CWE-290) in versions up to 5.27.5. This vulnerability allows an unauthenticated remote attacker to bypass intended security restrictions within the plugin's logic. The root cause involves insufficient verification of identity or session state, which can be exploited via network requests without any user interaction. Successful exploitation could allow an attacker to modify data or impact the availability of ticketing services. A patch is available in version 5.27.6.1.
Affected products
- Liquid Web / StellarWP Event Tickets <= 5.27.5
Timeline
- 2026-04-02: other: Reported by researcher endy
- 2026-05-02: disclosed: Initial disclosure by Patchstack
- 2026-05-02: patched: Patch released in version 5.27.6.1
- 2026-06-15: advisory: NVD advisory published