Impact
Missing authorization in the Nexcess Event Tickets plugin for WordPress allows attackers to reach functions that should be protected. This broken access control can lead to unauthorized creation, editing, or deletion of events, ticket types, or user data. Because the vulnerability permits control over core event management features, an attacker could disrupt or manipulate ticketing operations, potentially impacting revenue and customer information.
Affected Systems
Plug‑in version 5.28.5 and earlier of the Nexcess Event Tickets WordPress plugin are affected. The vulnerability applies to all WordPress sites running this plugin from any version up to and including 5.28.5. No specific WordPress core version is mentioned, but the issue exists in the plugin regardless of the host WordPress installation.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity flaw. The EPSS score of less than 1% shows low‑probability exploitation at present, and the flaw is not listed in the CISA KEV catalog. The likely attack vector involves a web‑based request to the plugin’s endpoints without proper authentication checks. An attacker may need initial access to the site privileged user) but can then misuse the plugin’s functions to elevate privileges or compromise data. Because the flaw stems from incorrectly configured security levels, the risk applies to any instance where the plugin’s internal checks are bypassed. Given the high CVSS score, administrators should consider remediation promptly even if exploitation is currently rare.
OpenCVE Enrichment