Impact
The Event Tickets and Registration plugin for WordPress contains a missing capability check on the Stripe OAuth return endpoint. This flaw allows an unauthenticated attacker to overwrite the site’s Stripe merchant credentials—access tokens, publishable keys, and account ID—by sending a crafted request. The attacker can then redirect all subsequent payment processing to their own Stripe account, potentially defrauding the site owner and users.
Affected Systems
Any WordPress installation that has the Event Tickets and Registration plugin version 5.27.4 or earlier is affected. This includes all releases up to and including 5.27.4. The vulnerability exists in the core plugin code and is not limited to specific configurations or customizations.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The exploit does not require authentication and targets a public-facing webhook endpoint, making it easily achievable by anyone who can send HTTP requests to the site. While EPSS data is not available, the straightforward nature of the attack and the lack of mitigation make the risk significant. The vulnerability is not listed in the CISA KEV catalog, but its impact justifies immediate attention.
OpenCVE Enrichment