Junglewise Threat Intelligence

CVE-2026-65567: Nexcess Event Tickets broken access control

CVE-2026-65567 · Severity: medium · CVSS 5.3 · Published 2026-07-27

Technologies: StellarWP Event Tickets. Vendors: StellarWP.

Executive brief

Event Tickets is a popular WordPress plugin used to manage event registrations and ticket sales. A security flaw in versions up to 5.29.0.1 allows unauthorized individuals to perform actions that should be restricted to administrators or specific users. While the impact is considered moderate, it could allow attackers to interfere with event management or ticket data without needing a password.

Technical details

The Event Tickets plugin for WordPress is vulnerable to broken access control (CWE-862) in versions up to and including 5.29.0.1. The vulnerability stems from a missing authorization check in a function that allows unauthenticated users to execute actions that should require higher privileges. An attacker can exploit this over the network without any user interaction or prior authentication. The impact is primarily on integrity, allowing unauthorized modifications. The issue is resolved in version 5.29.1.

Affected products

  • Nexcess / StellarWP / Liquid Web Event Tickets <= 5.29.0.1

Timeline

  • 2026-07-16: disclosed: Reported by Ananda Dhakal via Patchstack
  • 2026-07-24: advisory: Patchstack advisory published
  • 2026-07-27: advisory: NVD published CVE-2026-65567
  • 2026-07-27: patched: Version 5.29.1 confirmed as patched version

References

Related threats