Impact
The Ticketmeo – Sell Tickets – Event Ticketing plugin contains a stored cross‑site scripting flaw that allows an attacker with contributor‑level or higher WordPress access to inject arbitrary JavaScript into pages through the plugin’s shortcode attributes. The injected script is saved and executed whenever any user views a page containing the shortcode, enabling potential defacement, credential theft, or session hijacking. This attack leverages insufficient input sanitisation and output escaping on the plugin’s attributes, directly compromising the confidentiality and integrity of user interactions within the site.
Affected Systems
Vulnerable installations are WordPress sites running any Ticketmeo – Sell Tickets – Event Ticketing plugin version up to and including 2.3.6. No specific WordPress core version is implicated, but any site using those plugin releases is affected.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score is below 1 %, reflecting a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires authenticated contributor or higher access, so the attack surface is limited to privileged users or compromised contributor accounts. If an attacker achieves this, the embedded script will execute client‑side and can be used for data theft or to spread malicious payloads to other visitors.
OpenCVE Enrichment
EUVD