← WordPress Vulnerabilities
WordPress security by component

Event Tickets

Event Tickets is a WordPress component with 13 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: event-tickets

CVE-2026-65567: Event Tickets exposes an unauthenticated privileged operation

Event Tickets through 5.29.0.1 permits an unauthenticated request to reach a plugin operation without the required access-control check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.

PublishedJul 27, 2026
Known safe version5.29.1
Safe version
Jul 27, 2026 CVE-2026-65567
Event Tickets exposes an unauthenticated privileged operation
Event Tickets through 5.29.0.1 permits an unauthenticated request to reach a plugin operation without the required access-control check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.
5.29.1
CVE5.3
NVDPending
Jul 13, 2026 CVE-2026-57705
Event Tickets: A security weakness
Event Tickets is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.28.5.
5.28.5.1
CVE7.5
NVDPending
Jun 15, 2026 CVE-2026-42662
Event Tickets: A security weakness
Event Tickets is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.27.5.
5.27.6.1
CVE6.5
NVDPending
Oct 22, 2025 CVE-2025-62027
Event Tickets: A security weakness
Event Tickets is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Apr 01, 2025 CVE-2025-30794
Event Tickets: Cross-site scripting
Event Tickets is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Feb 21, 2025 CVE-2025-1402
Event Tickets and Registration: A security weakness
Event Tickets and Registration is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jan 30, 2025 CVE-2024-13457
Event Tickets and Registration: A security weakness
Event Tickets and Registration is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jan 02, 2025 CVE-2024-38762
Event Tickets: Cross-site request forgery
Event Tickets is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Mar 04, 2024 CVE-2024-1319
Events Tickets Plus: A security weakness
Events Tickets Plus is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Mar 04, 2024 CVE-2024-1316
Event Tickets and Registration: A security weakness
Event Tickets and Registration is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Feb 22, 2024 CVE-2024-1053
Event Tickets and Registration: A security weakness
Event Tickets and Registration is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jan 24, 2022 CVE-2021-25028
Event Tickets: A security weakness
Event Tickets is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.1
NVD6.1
Sep 08, 2019 CVE-2019-16120
Event Tickets: A security weakness
Event Tickets is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVD8.8