Junglewise Threat Intelligence

CVE-2026-78263: Event Tickets cross-site scripting in WordPress plugin

CVE-2026-78263 · Severity: high · CVSS 7.1 · Published 2026-08-24

Technologies: StellarWP Event Tickets. Vendors: StellarWP.

Executive brief

Event Tickets is a popular WordPress plugin for selling event tickets and managing bookings. This vulnerability allows unauthenticated attackers to inject malicious scripts into the website, which can be executed in the browsers of visitors and administrators. Successful attacks could steal customer data, compromise user accounts, or redirect visitors to phishing sites, impacting customer trust and business operations.

Technical details

This is an unauthenticated cross-site scripting (XSS) vulnerability in the Event Tickets WordPress plugin affecting versions up to 5.29.2.1. The vulnerability allows attackers to inject malicious JavaScript code that executes in the context of the affected website, though successful exploitation requires user interaction (e.g., clicking a malicious link or visiting a crafted page). The attack vector is network-based and does not require authentication or elevated privileges. Attackers can steal session cookies, perform actions on behalf of users, or redirect visitors to malicious sites. The vulnerability has been patched in version 5.29.3 and later, and a mitigation rule is available from Patchstack to block attacks.

Affected products

  • StellarWP Event Tickets <= 5.29.2.1

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched: Patched in version 5.29.3

References

Related threats