Impact
A contributed SQL injection flaw in WordPress Event Tickets allows an attacker to execute arbitrary SQL statements against the site database. This vulnerability arises from unsanitized input that leaks into database queries, enabling data theft, modification, or deletion. The weakness is classified as CWE‑89, a classic injection defect that can lead to significant confidentiality and integrity breaches.
Affected Systems
The issue affects the WordPress Event Tickets plugin up to and including version 5.29.5. Vendors affected include Nexcess:Event Tickets, and any implementation using these versions is vulnerable. The fix is incorporated in 5.29.5.1 and newer releases.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. Although EPSS data is not available, the lack of listing in the CISA KEV catalog does not reduce the risk, since the attack vector likely requires attacker access to a contributor account or compromised credentials. Once the vulnerable endpoint is reached, the attacker can inject SQL to read, modify, or delete arbitrary data. Given the high CVSS score and the potential for data exposure, the threat remains significant.
OpenCVE Enrichment