Executive brief
The Event Tickets Manager for WooCommerce plugin for WordPress, which allows businesses to sell and manage tickets for events, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to perform actions that should be restricted to administrators or specific staff members. Exploitation could lead to unauthorized changes to event data or ticket configurations, potentially disrupting ticket sales and business operations.
Technical details
A missing authorization vulnerability (CWE-862) exists in the WP Swings Event Tickets Manager for WooCommerce plugin through version 1.5.5. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this to perform actions that should require higher privileges, potentially leading to unauthorized data modification or service disruption. The issue is resolved in version 1.5.6.
Affected products
- WP Swings Event Tickets Manager for WooCommerce <= 1.5.5
Timeline
- 2026-04-28: other: Reported by researcher okndjo
- 2026-07-08: advisory: Patchstack advisory published
- 2026-07-13: disclosed: CVE published to NVD