CVE-2025-11517: Event Tickets and Registration <= 5.26.5 - Unauthenticated Ticket Payment Bypass
The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.26.5. This is due to the /wp-json/tribe/tickets/v1/commerce/free/order endpoint not verifying that a ticket type should be free allowing the user to bypass the payment. This makes it possible for unauthenticated attackers to obtain access to paid tickets, without paying for them, causing a loss of revenue for the target.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11517?
CVE-2025-11517 is a high-severity vulnerability that allows payment bypass in affected versions.
How do I fix CVE-2025-11517?
To fix CVE-2025-11517, upgrade the Event Tickets and Registration plugin to version 5.26.6 or later.
Which versions are affected by CVE-2025-11517?
CVE-2025-11517 affects all versions of Event Tickets and Registration up to and including 5.26.5.
What types of attacks can CVE-2025-11517 facilitate?
CVE-2025-11517 can facilitate unauthorized ticket purchases by bypassing payment verification.
Is CVE-2025-11517 specific to WordPress?
Yes, CVE-2025-11517 specifically affects the Event Tickets and Registration plugin for WordPress.