HomeWordPress vulnerabilitiesEvent Tickets and Registration
Event Tickets and Registration vulnerabilities
Event Tickets and Registration has 16 known vulnerabilities in this database. The most recent published record is dated 5 Oct 2026.
- Known vulnerabilities
- 16
- Active installs
- 90,000+
- Latest version
- 5.30.0
- Last updated
- 30 Sep 2026
- Most recent
- 5 Oct 2026
No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Broken access control CVE-2026-104675 | Medium 4.3 | Up to 5.30.0 | No fixed version yet | 2 d ago |
| SQL injection CVE-2026-97634 | Medium 6.5 | Up to 5.29.5 | Fixed in a later version (latest 5.30.0) | 5 d ago |
| SQL injection CVE-2026-97287 | High 8.5 | Up to 5.29.5 | Fixed in a later version (latest 5.30.0) | 7 d ago |
| Broken access control CVE-2026-3174 | High 7.5 | Up to 5.27.4 | Fixed in a later version (latest 5.30.0) | 8 Sep 2026 |
| Broken access control CVE-2026-14822 | Medium 5.3 | Before 5.29.0.1 | Fixed in 5.29.0.1 | 1 Aug 2026 |
| Broken access control CVE-2026-14823 | Low 2.2 | Before 5.29.0.1 | Fixed in 5.29.0.1 | 1 Aug 2026 |
| Cross-site scripting (XSS) CVE-2026-14819 | Low 3.5 | Before 5.28.4 | Fixed in 5.28.4 | 28 Jul 2026 |
| Broken access control CVE-2025-11517 | High 7.5 | Up to 5.26.5 | Fixed in a later version (latest 5.30.0) | 18 Oct 2025 |
| Broken access control CVE-2025-1402 | Medium 5.3 | Before 5.19.1.2 | Fixed in 5.19.1.2 | 21 Feb 2025 |
| Broken access control CVE-2024-13457 | Medium 5.3 | Before 5.18.1.1 | Fixed in 5.18.1.1 | 30 Jan 2025 |
| Sensitive data exposure CVE-2024-2261 | Medium 4.3 | Up to 5.8.2 | Fixed in a later version (latest 5.30.0) | 9 Apr 2024 |
| Security weakness CVE-2024-1316 | Medium 6.5 | Before 5.9.1 | Fixed in 5.9.1 | 4 Mar 2024 |
| Security weakness CVE-2024-1319 | Medium 4.3 | Before 5.9.1 | Fixed in 5.9.1 | 4 Mar 2024 |
| Broken access control CVE-2024-1053 | Medium 4.3 | Before 5.8.2 | Fixed in 5.8.2 | 22 Feb 2024 |
| Open redirect CVE-2021-25028 | Medium 6.1 | Before 5.2.2 | Fixed in 5.2.2 | 24 Jan 2022 |
| CSV injection CVE-2019-16120 | High 8.8 | Before 4.10.7.2 | Fixed in 4.10.7.2 | 8 Sep 2019 |
Read the published descriptions
- CVE-2026-104675, 5 Oct 2026
- Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0. CVE record
- CVE-2026-97634, 2 Oct 2026
- The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.29.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. A Contributor-level user can reach the vulnerable code path by supplying a post_id they authored, as the can_access_page() gate requires only post authorship rather than the edit_others_posts capability for post owners. CVE record
- CVE-2026-97287, 30 Sep 2026
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Blind SQL Injection.This issue affects Event Tickets: from n/a through 5.29.5. CVE record
- CVE-2026-3174, 8 Sep 2026
- The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant credentials (access tokens, publishable keys, and account ID), diverting all subsequent payment processing to the attacker's Stripe account. CVE record
- CVE-2026-14822, 1 Aug 2026
- The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders. CVE record
- CVE-2026-14823, 1 Aug 2026
- The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of events they do not own. CVE record
- CVE-2026-14819, 28 Jul 2026
- The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations. CVE record
- CVE-2025-11517, 18 Oct 2025
- The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.26.5. This is due to the /wp-json/tribe/tickets/v1/commerce/free/order endpoint not verifying that a ticket type should be free allowing the user to bypass the payment. This makes it possible for unauthenticated attackers to obtain access to paid tickets, without paying for them, causing a loss of revenue for the target. CVE record
- CVE-2025-1402, 21 Feb 2025
- The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function in all versions up to, and including, 5.19.1.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary Attendee tickets. CVE record
- CVE-2024-13457, 30 Jan 2025
- The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view order details of orders they did not place, which includes ticket prices, user emails and order date. CVE record
- CVE-2024-2261, 9 Apr 2024
- The Event Tickets and Registration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.8.2 via the RSVP functionality. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including emails and street addresses. CVE record
- CVE-2024-1316, 4 Mar 2024
- The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed events). CVE record
- CVE-2024-1319, 4 Mar 2024
- The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts). CVE record
- CVE-2024-1053, 22 Feb 2024
- The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it possible for authenticated attackers, with contributor-level access and above, to email the attendees list to themselves. CVE record
- CVE-2021-25028, 24 Jan 2022
- The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue CVE record
- CVE-2019-16120, 8 Sep 2019
- CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature. CVE record
What to do if you run Event Tickets and Registration
If you run Event Tickets and Registration, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Event Tickets and Registration vulnerabilities
Free. We email you when a new vulnerability is published for Event Tickets and Registration, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.