Description
Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through <= 5.28.5.
Published: 2026-07-13
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing authorization in the Nexcess Event Tickets plugin for WordPress allows attackers to reach functions that should be protected. This broken access control can lead to unauthorized creation, editing, or deletion of events, ticket types, or user data. Because the vulnerability permits control over core event management features, an attacker could disrupt or manipulate ticketing operations, potentially impacting revenue and customer information.

Affected Systems

Plug‑in version 5.28.5 and earlier of the Nexcess Event Tickets WordPress plugin are affected. The vulnerability applies to all WordPress sites running this plugin from any version up to and including 5.28.5. No specific WordPress core version is mentioned, but the issue exists in the plugin regardless of the host WordPress installation.

Risk and Exploitability

The CVSS score of 7.5 indicates a high‑severity flaw. The EPSS score of less than 1% shows low‑probability exploitation at present, and the flaw is not listed in the CISA KEV catalog. The likely attack vector involves a web‑based request to the plugin’s endpoints without proper authentication checks. An attacker may need initial access to the site privileged user) but can then misuse the plugin’s functions to elevate privileges or compromise data. Because the flaw stems from incorrectly configured security levels, the risk applies to any instance where the plugin’s internal checks are bypassed. Given the high CVSS score, administrators should consider remediation promptly even if exploitation is currently rare.

Generated by OpenCVE AI on August 1, 2026 at 10:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Event Tickets plugin to a version newer than 5.28.5.
  • Ensure that only users with the appropriate WordPress roles can access event‑management endpoints; adjust plugin permissions if necessary.
  • Review existing event configurations for unauthorized entries and correct any that were created with elevated privileges.

Generated by OpenCVE AI on August 1, 2026 at 10:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Nexcess
Nexcess event Tickets
Wordpress
Wordpress wordpress
Vendors & Products Nexcess
Nexcess event Tickets
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through <= 5.28.5.
Title WordPress Event Tickets plugin <= 5.28.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Nexcess Event Tickets
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:51.185Z

Reserved: 2026-06-25T08:03:56.314Z

Link: CVE-2026-57705

cve-icon Vulnrichment

Updated: 2026-07-13T16:02:11.392Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses