Impact
Missing authorization in the WP Swings Event Tickets Manager for WooCommerce plugin allows users to exploit incorrectly configured access control security levels. As a result, individuals who do not have the proper privileges may gain access to functionalities that should be restricted, potentially enabling unauthorized management of events and, by extension, sensitive event data.
Affected Systems
The vulnerability affects the WordPress plugin Event Tickets Manager for WooCommerce from all prior releases through version 1.5.5, as provided by the vendor WP Swings.
Risk and Exploitability
The CVSS score of 6.5 places this issue in the moderate range, while an EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis. The flaw is not listed in the CISA KEV catalog. The likely attack vector is inferred to be web‑based interactions with the plugin’s administrative and event‑management endpoints, without requiring local access. An attacker who identifies the exposed endpoints could bypass intended access controls to perform unauthorized actions.
OpenCVE Enrichment