Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesEvent Tickets and Registration

Event Tickets and Registration vulnerabilities

Event Tickets and Registration has 16 known vulnerabilities in this database. The most recent published record is dated 5 Oct 2026.

Known vulnerabilities
16
Active installs
90,000+
Latest version
5.30.0
Last updated
30 Sep 2026
Most recent
5 Oct 2026

No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Broken access control
CVE-2026-104675
Medium 4.3Up to 5.30.0No fixed version yet2 d ago
SQL injection
CVE-2026-97634
Medium 6.5Up to 5.29.5Fixed in a later version (latest 5.30.0)5 d ago
SQL injection
CVE-2026-97287
High 8.5Up to 5.29.5Fixed in a later version (latest 5.30.0)7 d ago
Broken access control
CVE-2026-3174
High 7.5Up to 5.27.4Fixed in a later version (latest 5.30.0)8 Sep 2026
Broken access control
CVE-2026-14822
Medium 5.3Before 5.29.0.1Fixed in 5.29.0.11 Aug 2026
Broken access control
CVE-2026-14823
Low 2.2Before 5.29.0.1Fixed in 5.29.0.11 Aug 2026
Cross-site scripting (XSS)
CVE-2026-14819
Low 3.5Before 5.28.4Fixed in 5.28.428 Jul 2026
Broken access control
CVE-2025-11517
High 7.5Up to 5.26.5Fixed in a later version (latest 5.30.0)18 Oct 2025
Broken access control
CVE-2025-1402
Medium 5.3Before 5.19.1.2Fixed in 5.19.1.221 Feb 2025
Broken access control
CVE-2024-13457
Medium 5.3Before 5.18.1.1Fixed in 5.18.1.130 Jan 2025
Sensitive data exposure
CVE-2024-2261
Medium 4.3Up to 5.8.2Fixed in a later version (latest 5.30.0)9 Apr 2024
Security weakness
CVE-2024-1316
Medium 6.5Before 5.9.1Fixed in 5.9.14 Mar 2024
Security weakness
CVE-2024-1319
Medium 4.3Before 5.9.1Fixed in 5.9.14 Mar 2024
Broken access control
CVE-2024-1053
Medium 4.3Before 5.8.2Fixed in 5.8.222 Feb 2024
Open redirect
CVE-2021-25028
Medium 6.1Before 5.2.2Fixed in 5.2.224 Jan 2022
CSV injection
CVE-2019-16120
High 8.8Before 4.10.7.2Fixed in 4.10.7.28 Sep 2019
Read the published descriptions
CVE-2026-104675, 5 Oct 2026
Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0. CVE record
CVE-2026-97634, 2 Oct 2026
The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.29.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. A Contributor-level user can reach the vulnerable code path by supplying a post_id they authored, as the can_access_page() gate requires only post authorship rather than the edit_others_posts capability for post owners. CVE record
CVE-2026-97287, 30 Sep 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Blind SQL Injection.This issue affects Event Tickets: from n/a through 5.29.5. CVE record
CVE-2026-3174, 8 Sep 2026
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant credentials (access tokens, publishable keys, and account ID), diverting all subsequent payment processing to the attacker's Stripe account. CVE record
CVE-2026-14822, 1 Aug 2026
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders. CVE record
CVE-2026-14823, 1 Aug 2026
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of events they do not own. CVE record
CVE-2026-14819, 28 Jul 2026
The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations. CVE record
CVE-2025-11517, 18 Oct 2025
The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.26.5. This is due to the /wp-json/tribe/tickets/v1/commerce/free/order endpoint not verifying that a ticket type should be free allowing the user to bypass the payment. This makes it possible for unauthenticated attackers to obtain access to paid tickets, without paying for them, causing a loss of revenue for the target. CVE record
CVE-2025-1402, 21 Feb 2025
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function in all versions up to, and including, 5.19.1.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary Attendee tickets. CVE record
CVE-2024-13457, 30 Jan 2025
The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view order details of orders they did not place, which includes ticket prices, user emails and order date. CVE record
CVE-2024-2261, 9 Apr 2024
The Event Tickets and Registration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.8.2 via the RSVP functionality. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including emails and street addresses. CVE record
CVE-2024-1316, 4 Mar 2024
The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed events). CVE record
CVE-2024-1319, 4 Mar 2024
The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts). CVE record
CVE-2024-1053, 22 Feb 2024
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it possible for authenticated attackers, with contributor-level access and above, to email the attendees list to themselves. CVE record
CVE-2021-25028, 24 Jan 2022
The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue CVE record
CVE-2019-16120, 8 Sep 2019
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature. CVE record

What to do if you run Event Tickets and Registration

If you run Event Tickets and Registration, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Event Tickets and Registration vulnerabilities

Free. We email you when a new vulnerability is published for Event Tickets and Registration, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support