Impact
This vulnerability is a stored cross‑site scripting flaw caused by improper input neutralization in the My Tickets plugin. An attacker can inject malicious JavaScript that will be rendered in pages viewed by other users, enabling session hijacking, cookie theft, or phishing attacks. The flaw arises from unescaped data stored by the plugin, which is later displayed without proper sanitization.
Affected Systems
The My Tickets plugin for WordPress sold by Joe Dolson is affected in all releases up to and including version 2.0.22. Users running those versions should consider the vulnerability relevant to their WordPress installations.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of <1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to submit tainted input through a form or administrative interface that the plugin stores and later renders. Once injected scripts execute in the victim's browser, the attacker gains the ability to deface content or hijack sessions.
OpenCVE Enrichment
EUVD