Impact
This issue is a missing authorization flaw that allows an attacker to bypass the expected access controls on the Event Tickets plugin. A user who can exploit the flaw may gain the ability to create, edit, or delete event tickets and their associated data, compromising the integrity and privacy of event information. The weakness maps to CWE‑862, an authorization issue that can lead to unauthorized data manipulation.
Affected Systems
The vulnerability affects the WordPress Event Tickets plugin from its earliest release up to and including version 5.30.0.1, released by Liquid Web and StellarWP. Any WordPress site that has installed this plugin in a version within that range is impacted; newer releases are not affected.
Risk and Exploitability
The CVSS score of 5.4 classifies the flaw as moderate in severity. EPSS data is not available, so precise exploitation likelihood cannot be quantified, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector involves a user who has authenticated with a role that has access to event management features; by exploiting the missing checks an attacker could manipulate tickets in ways that the site administrator did not intend. Such misuse could expose sensitive attendee data and disrupt legitimate event operations.
OpenCVE Enrichment