WordPress security by component
easy-paypal-events-tickets
Plugin description
easy-paypal-events-tickets is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published May 04, 2026; the highest CVE/CNA score is 8.7.
Plugin slug:
easy-paypal-events-ticketsLatest vulnerability
CVE-2026-41471: easy-paypal-events-tickets: Sensitive information exposure
easy-paypal-events-tickets is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The published affected range is < 1.4.0.
| Safe version |
|
||
|---|---|---|---|
| May 04, 2026 |
CVE-2026-41471
easy-paypal-events-tickets: Sensitive information exposure
easy-paypal-events-tickets is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The published affected range is < 1.4.0.
|
1.4.0 |
CVE8.2
NVDPending
|
| May 04, 2026 |
CVE-2026-32834
easy-paypal-events-tickets: Privilege escalation or authentication bypass
easy-paypal-events-tickets is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is < 1.4.0.
|
1.4.0 |
CVE8.7
NVDPending
|
| May 07, 2025 |
CVE-2025-47519
Easy PayPal Events: Cross-site request forgery
Easy PayPal Events is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 25, 2024 |
CVE-2024-8476
Easy PayPal Events: Cross-site request forgery
Easy PayPal Events is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|