Description
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant credentials (access tokens, publishable keys, and account ID), diverting all subsequent payment processing to the attacker's Stripe account.
Published: 2026-09-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Credential Modification and Payment Diversion
Action: Apply Patch
AI Analysis

Impact

The Event Tickets and Registration plugin for WordPress contains a missing capability check on the Stripe OAuth return endpoint. This flaw allows an unauthenticated attacker to overwrite the site’s Stripe merchant credentials—access tokens, publishable keys, and account ID—by sending a crafted request. The attacker can then redirect all subsequent payment processing to their own Stripe account, potentially defrauding the site owner and users.

Affected Systems

Any WordPress installation that has the Event Tickets and Registration plugin version 5.27.4 or earlier is affected. This includes all releases up to and including 5.27.4. The vulnerability exists in the core plugin code and is not limited to specific configurations or customizations.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The exploit does not require authentication and targets a public-facing webhook endpoint, making it easily achievable by anyone who can send HTTP requests to the site. While EPSS data is not available, the straightforward nature of the attack and the lack of mitigation make the risk significant. The vulnerability is not listed in the CISA KEV catalog, but its impact justifies immediate attention.

Generated by OpenCVE AI on September 8, 2026 at 12:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Event Tickets and Registration plugin to the latest version (at least 5.27.5) where the capability check has been restored.
  • Verify that all WordPress sites no longer run a version 5.27.4 or earlier of the plugin before completing the update.
  • If the credentials have already been compromised, revoke the old Stripe merchant keys and generate new ones to prevent unauthorized payment processing.

Generated by OpenCVE AI on September 8, 2026 at 12:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Stellarwp
Stellarwp event Tickets And Registration
Wordpress
Wordpress wordpress
Vendors & Products Stellarwp
Stellarwp event Tickets And Registration
Wordpress
Wordpress wordpress

Tue, 08 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant credentials (access tokens, publishable keys, and account ID), diverting all subsequent payment processing to the attacker's Stripe account.
Title Event Tickets and Registration <= 5.27.4 - Missing Authorization to Unauthenticated Stripe Credentials Update
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Stellarwp Event Tickets And Registration
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-09T15:58:32.668Z

Reserved: 2026-02-24T23:47:23.549Z

Link: CVE-2026-3174

cve-icon Vulnrichment

Updated: 2026-09-09T15:58:22.071Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T12:16:54.620

Modified: 2026-09-09T16:17:02.893

Link: CVE-2026-3174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:35:02Z

Weaknesses