Impact
The StellarWP Event Tickets plugin up to version 5.26.3 contains a missing authorization flaw, identified as CWE‑862, that allows users to perform privileged actions beyond their permissions. Attackers could create, modify, or delete tickets without proper access checks, thereby compromising the integrity of event management.
Affected Systems
Any WordPress site running StellarWP Event Tickets plugin with a version equal to or less than 5.26.3 is affected. The vulnerability applies to all installations that have the plugin enabled, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate impact, while the EPSS score of less than 1% signals a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves interacting with the plugin’s ticket management endpoints, and the attacker only needs web access to the site; authentication may or may not be required depending on the site’s role configuration.
OpenCVE Enrichment