Description
Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets Manager for WooCommerce: from n/a through <= 1.5.5.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing authorization in the WP Swings Event Tickets Manager for WooCommerce plugin allows users to exploit incorrectly configured access control security levels. As a result, individuals who do not have the proper privileges may gain access to functionalities that should be restricted, potentially enabling unauthorized management of events and, by extension, sensitive event data.

Affected Systems

The vulnerability affects the WordPress plugin Event Tickets Manager for WooCommerce from all prior releases through version 1.5.5, as provided by the vendor WP Swings.

Risk and Exploitability

The CVSS score of 6.5 places this issue in the moderate range, while an EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis. The flaw is not listed in the CISA KEV catalog. The likely attack vector is inferred to be web‑based interactions with the plugin’s administrative and event‑management endpoints, without requiring local access. An attacker who identifies the exposed endpoints could bypass intended access controls to perform unauthorized actions.

Generated by OpenCVE AI on July 31, 2026 at 11:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Event Tickets Manager for WooCommerce to the latest patched version that addresses the access‑control flaw.
  • Restrict the plugin’s event‑management capabilities to trusted administrator roles, ensuring that only authorized users possess the required permissions.
  • If an upgrade is not immediately possible, disable the plugin or block its administrative endpoints via web‑server configuration to prevent exploitation until the vulnerability is remediated.

Generated by OpenCVE AI on July 31, 2026 at 11:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp Swings
Wp Swings event Tickets Manager For Woocommerce
Vendors & Products Wordpress
Wordpress wordpress
Wp Swings
Wp Swings event Tickets Manager For Woocommerce

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets Manager for WooCommerce: from n/a through <= 1.5.5.
Title WordPress Event Tickets Manager for WooCommerce plugin <= 1.5.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Wp Swings Event Tickets Manager For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:42:38.175Z

Reserved: 2026-06-24T12:46:07.752Z

Link: CVE-2026-57400

cve-icon Vulnrichment

Updated: 2026-07-13T13:42:35.110Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses