Description
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant credentials (access tokens, publishable keys, and account ID), diverting all subsequent payment processing to the attacker's Stripe account.
Published: 2026-09-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Event Tickets and Registration plugin for WordPress contains a missing capability check on the Stripe OAuth return endpoint. This flaw allows an unauthenticated attacker to overwrite the site’s Stripe merchant credentials—access tokens, publishable keys, and account ID—by sending a crafted request. The attacker can then redirect all subsequent payment processing to their own Stripe account, potentially defrauding the site owner and users.

Affected Systems

Any WordPress installation that has the Event Tickets and Registration plugin version 5.27.4 or earlier is affected. This includes all releases up to and including 5.27.4. The vulnerability exists in the core plugin code and is not limited to specific configurations or customizations.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The exploit does not require authentication and targets a public-facing webhook endpoint, making it easily achievable by anyone who can send HTTP requests to the site. While EPSS data is not available, the straightforward nature of the attack and the lack of mitigation make the risk significant. The vulnerability is not listed in the CISA KEV catalog, but its impact justifies immediate attention.

Generated by OpenCVE AI on September 8, 2026 at 12:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Event Tickets and Registration plugin to the latest version (at least 5.27.5) where the capability check has been restored.
  • Verify that all WordPress sites no longer run a version 5.27.4 or earlier of the plugin before completing the update.
  • If the credentials have already been compromised, revoke the old Stripe merchant keys and generate new ones to prevent unauthorized payment processing.

Generated by OpenCVE AI on September 8, 2026 at 12:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant credentials (access tokens, publishable keys, and account ID), diverting all subsequent payment processing to the attacker's Stripe account.
Title Event Tickets and Registration <= 5.27.4 - Missing Authorization to Unauthenticated Stripe Credentials Update
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-08T11:29:59.815Z

Reserved: 2026-02-24T23:47:23.549Z

Link: CVE-2026-3174

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T12:16:54.620

Modified: 2026-09-08T12:16:54.620

Link: CVE-2026-3174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T12:30:17Z

Weaknesses