Executive brief
The Event Tickets plugin for WordPress, used to manage event registrations and ticketing, contains a security flaw in its access control system. This vulnerability allows unauthorized individuals to perform actions that should be restricted to administrators or authorized staff. An attacker could exploit this to modify ticket settings or interfere with event management without needing a password or special account.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Nexcess Event Tickets plugin for WordPress through version 5.28.5. The flaw is rooted in incorrectly configured access control security levels, which fail to validate user permissions before executing certain functions. An unauthenticated attacker can exploit this over the network to perform actions with higher privileges, potentially modifying data or settings within the plugin. The issue is resolved in version 5.28.5.1.
Affected products
- Nexcess / StellarWP Event Tickets <= 5.28.5
Timeline
- 2026-06-19: other: Vulnerability reported by researcher dunvu0
- 2026-07-08: advisory: Patchstack published initial advisory
- 2026-07-13: disclosed: CVE published to NVD dataset