Impact
The Event Tickets plugin allows unauthenticated users to inject arbitrary code through the interface, creating a classic Cross‑Site Scripting flaw (CWE‑79). Functionality exposed by the plugin can display or store user input, so attackers can embed JavaScript that executes in the browser context of any visitor, enabling session theft, defacement, or malicious redirects.
Affected Systems
WordPress installations that have the Event Tickets plugin version 5.29.2.1 or earlier installed by Nexcess. No other products are indicated as affected.
Risk and Exploitability
The CVSS score of 7.1 classifies this flaw as high severity, while no EPSS score is available, meaning the current exploitation probability is unavailable. The vulnerability is not listed in CISA’s KEV catalog. Attackers can trigger the XSS without needing any credentials by manipulating input fields in the plugin’s interface, and the script will be reflected or stored for further users to execute.
OpenCVE Enrichment