Description
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
Published: 2026-08-24
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting (XSS)
Action: Patch Now
AI Analysis

Impact

The Event Tickets plugin allows unauthenticated users to inject arbitrary code through the interface, creating a classic Cross‑Site Scripting flaw (CWE‑79). Functionality exposed by the plugin can display or store user input, so attackers can embed JavaScript that executes in the browser context of any visitor, enabling session theft, defacement, or malicious redirects.

Affected Systems

WordPress installations that have the Event Tickets plugin version 5.29.2.1 or earlier installed by Nexcess. No other products are indicated as affected.

Risk and Exploitability

The CVSS score of 7.1 classifies this flaw as high severity, while no EPSS score is available, meaning the current exploitation probability is unavailable. The vulnerability is not listed in CISA’s KEV catalog. Attackers can trigger the XSS without needing any credentials by manipulating input fields in the plugin’s interface, and the script will be reflected or stored for further users to execute.

Generated by OpenCVE AI on August 24, 2026 at 22:46 UTC.

Remediation

Vendor Solution

Update the WordPress Event Tickets Plugin to the latest available version (at least 5.29.3).


OpenCVE Recommended Actions

  • Update the WordPress Event Tickets plugin to version 5.29.3 or newer.
  • Remove any old plugin files to ensure no legacy code remains in the site directory.
  • Monitor the site for other unvalidated input points that could lead to XSS.

Generated by OpenCVE AI on August 24, 2026 at 22:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Nexcess
Nexcess event Tickets
Wordpress
Wordpress wordpress
Vendors & Products Nexcess
Nexcess event Tickets
Wordpress
Wordpress wordpress

Mon, 24 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
Title WordPress Event Tickets plugin <= 5.29.2.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Nexcess Event Tickets
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-25T19:23:05.855Z

Reserved: 2026-08-24T07:37:35.411Z

Link: CVE-2026-78263

cve-icon Vulnrichment

Updated: 2026-08-25T18:32:44.157Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T22:17:20.133

Modified: 2026-08-26T16:19:05.917

Link: CVE-2026-78263

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T23:00:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')