Impact
The vulnerability is a missing authorization flaw in the WordPress Event Tickets plugin which permits unauthorized users to perform privileged actions such as creating events or changing event visibility. This flaw stems from incorrectly configured access control level checks within the plugin code. The result is a potential privilege escalation for attackers, allowing them to abuse event management functions.
Affected Systems
The issue affects the Liquid Web / StellarWP Event Tickets plugin for WordPress, versions from the earliest version through 5.30.0. Any WordPress site that uses one of those affected plugin versions and exposes the plugin's endpoint features is vulnerable.
Risk and Exploitability
The CVSS base score of 4.3 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw resides in the plugin's web-accessible action handlers, the likely attack vector involves HTTP requests made by unauthenticated or minimally privileged users. An attacker could exploit the broken access controls to gain unauthorized control over event resources, potentially leading to broader compromise or denial of service if enough privileged actions are abused.
OpenCVE Enrichment