Impact
The Event Tickets Manager for WooCommerce plugin suffers from a classic broken access control flaw (CWE-862). A user can invoke privileged ticket‑management functions without authenticating, allowing creation, modification, or deletion of event tickets and potentially exposing sensitive ticket information.
Affected Systems
All WordPress installations running WP Swings' Event Tickets Manager for WooCommerce plugin version 1.5.3 or earlier are affected. The vulnerability is limited to these plugin versions; later releases are not impacted.
Risk and Exploitability
With a CVSS score of 7.5, the severity is considered high. The EPSS score of less than 1% signals a low predicted likelihood of exploitation at present, and the issue is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely through the plugin’s web interface, as an unauthenticated user can call management endpoints directly.
OpenCVE Enrichment