Description
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders.
Published: 2026-08-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Event Tickets and Registration WordPress plugin fails to enforce authorization on a specific order‑management REST endpoint, enabling any unauthenticated user to alter the status of an existing order. This flaw permits an attacker to modify the integrity of order data, potentially changing an order from pending to completed or deleted without permission.

Affected Systems

WordPress sites that have the Event Tickets and Registration plugin installed and running a version earlier than 5.29.0.1 are affected. Sites using any older release of the plugin with the default configuration are vulnerable to unauthenticated manipulation of order statuses.

Risk and Exploitability

The exploitation likelihood is low, as indicated by an EPSS score of less than 1%, and the CVSS score of 5.3 indicates moderate severity. The vulnerability does not appear in the CISA KEV catalog, suggesting no publicly documented exploits. However, the REST endpoint is reachable without authentication, making the attack vector simple: an attacker can send crafted HTTP requests directly to the endpoint to change order states. While the EPSS score suggests a lower probability of attack, sites remain at risk of unauthorized data modification if the plugin is not updated.

Generated by OpenCVE AI on August 5, 2026 at 19:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Event Tickets and Registration plugin to version 5.29.0.1 or newer.
  • Restrict access to the order‑management REST endpoint by disabling unnecessary HTTP methods or applying IP or role based access controls.
  • Configure monitoring or logging of order status changes to detect any unauthorized modifications.

Generated by OpenCVE AI on August 5, 2026 at 19:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-305

Wed, 05 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 02 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-305

Sat, 01 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders.
Title Event Tickets < 5.29.0.1 - Unauthenticated PayPal Order Status Manipulation
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-05T16:18:33.721Z

Reserved: 2026-07-06T08:45:39.950Z

Link: CVE-2026-14822

cve-icon Vulnrichment

Updated: 2026-08-05T15:42:14.483Z

cve-icon NVD

Status : Received

Published: 2026-08-01T07:16:30.623

Modified: 2026-08-05T17:16:41.697

Link: CVE-2026-14822

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T19:30:05Z

Weaknesses