← WordPress Vulnerabilities
WordPress security by component

easy-paypal-events-tickets

easy-paypal-events-tickets is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published May 04, 2026; the highest CVE/CNA score is 8.7.

Plugin slug: easy-paypal-events-tickets

CVE-2026-41471: easy-paypal-events-tickets: Sensitive information exposure

easy-paypal-events-tickets is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The published affected range is < 1.4.0.

PublishedMay 04, 2026
Known safe version1.4.0
Safe version
May 04, 2026 CVE-2026-41471
easy-paypal-events-tickets: Sensitive information exposure
easy-paypal-events-tickets is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The published affected range is < 1.4.0.
1.4.0
CVE8.2
NVDPending
May 04, 2026 CVE-2026-32834
easy-paypal-events-tickets: Privilege escalation or authentication bypass
easy-paypal-events-tickets is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is < 1.4.0.
1.4.0
CVE8.7
NVDPending
May 07, 2025 CVE-2025-47519
Easy PayPal Events: Cross-site request forgery
Easy PayPal Events is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Sep 25, 2024 CVE-2024-8476
Easy PayPal Events: Cross-site request forgery
Easy PayPal Events is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending