Impact
Unauthenticated Cross Site Scripting (XSS) is present in WordPress Event Tickets plugin versions up to 5.29.4. The flaw permits injection of malicious scripts into web pages viewed by other users, enabling session hijacking, defacement, or phishing. The vulnerability stems from insufficient input sanitization and is classified under CWE‑79.
Affected Systems
Vulnerable deployments use the WordPress Event Tickets plugin version 5.29.4 or earlier, including sites hosted by Nexcess. WordPress installations that include the plugin are at risk if not updated to at least 5.29.5.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity for client‑side impact. Because the vulnerability is unauthenticated, any user can exploit it by accessing a crafted URL or page. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, yet the ability to run arbitrary JavaScript in users’ browsers makes exploitation likely where the plugin is exposed.
OpenCVE Enrichment