WordPress security by component
Event Tickets and Registration
Plugin description
Event Tickets and Registration is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 7.5.
Plugin slug:
event-tickets-and-registrationLatest vulnerability
CVE-2026-14819: Event Tickets Editors can store script in ticket history on multisite
Event Tickets and Registration before 5.28.4 fails to escape an Editor-controlled event title when rendering it in a ticket history log on WordPress multisite. An Editor can store script markup in the title, and that script executes in the site origin when a higher-privileged user views the affected history entry. The WPScan CNA record does not disclose the request endpoint, title parameter, storage function or history-rendering function.
| Safe version |
|
||
|---|---|---|---|
| Jul 28, 2026 |
CVE-2026-14819
Event Tickets Editors can store script in ticket history on multisite
Event Tickets and Registration before 5.28.4 fails to escape an Editor-controlled event title when rendering it in a ticket history log on WordPress multisite. An Editor can store script markup in the title, and that script executes in the site origin when a higher-privileged user views the affected history entry. The WPScan CNA record does not disclose the request endpoint, title parameter, storage function or history-rendering function.
|
5.28.4 |
CVE3.5
NVDPending
|
| Oct 18, 2025 |
CVE-2025-11517
Event Tickets and Registration: A security weakness
Event Tickets and Registration is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Apr 09, 2024 |
CVE-2024-2261
Event Tickets and Registration: Sensitive information exposure
Event Tickets and Registration is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE4.3
NVDPending
|