Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.8.5.
Published: 2026-01-22
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in the Vollstart Event Tickets with Ticket Scanner WordPress plugin is an improper control over code generation, allowing an attacker to inject arbitrary code that is then executed by the server. This flaw is defined as CWE‑94, indicating that the application fails to validate or sanitize code it runs. When exploited, the attacker can run any command with the privileges of the Wordpress installation, potentially compromising the entire site, its database, and any connected services.

Affected Systems

All installations of the Vollstart Event Tickets with Ticket Scanner plugin up to and including version 2.8.5 are affected. An attacker does not need to know the exact WordPress version; the vulnerability exists in every site that has the plugin loaded within that version range, regardless of the site’s configuration or the roles of the users who interact with the plugin.

Risk and Exploitability

The CVSS score is 9, which indicates critical severity. The EPSS score is less than 1%, showing a very low but non-zero likelihood of exploitation according to the EPSS model. The vulnerability is not listed in the CISA KEV catalog, meaning there is no documented active exploitation in the wild currently. The likely attack vector is remote, as an attacker can supply malicious code through the plugin’s public interfaces or API endpoints. Successful exploitation does not require authentication beyond any normal access to the plugin, so the risk remains high for any publicly accessible installation.

Generated by OpenCVE AI on April 28, 2026 at 09:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Event Tickets with Ticket Scanner plugin to the latest version (at least 2.8.6).
  • If an update is not immediately possible, restrict the plugin’s functionality by disabling it for non‑admin users or temporarily deactivating it until a patch is applied.
  • Apply server‑side input validation or set web application firewall rules to block suspicious payloads that could be interpreted as executable code within the plugin’s context.

Generated by OpenCVE AI on April 28, 2026 at 09:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.8.3. Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.8.5.
Title WordPress Event Tickets with Ticket Scanner plugin <= 2.8.3 - Remote Code Execution (RCE) vulnerability WordPress Event Tickets with Ticket Scanner plugin <= 2.8.5 - Remote Code Execution (RCE) vulnerability

Wed, 28 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Vollstart
Vollstart event Tickets With Ticket Scanner
Wordpress
Wordpress wordpress
Vendors & Products Vollstart
Vollstart event Tickets With Ticket Scanner
Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.8.3.
Title WordPress Event Tickets with Ticket Scanner plugin <= 2.8.3 - Remote Code Execution (RCE) vulnerability
Weaknesses CWE-94
References

Subscriptions

Vollstart Event Tickets With Ticket Scanner
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T19:54:52.096Z

Reserved: 2025-12-15T10:00:54.715Z

Link: CVE-2025-68015

cve-icon Vulnrichment

Updated: 2026-01-28T17:19:56.293Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:07.817

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-68015

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T10:00:06Z

Weaknesses