CVE-2025-1402: Event Tickets and Registration <= 5.19.1.1 - Missing Authorization to Ticket Deletion
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajaxticketdelete' function in all versions up to, and including, 5.19.1.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary Attendee tickets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1402?
CVE-2025-1402 has a high severity rating due to the potential for unauthorized data loss.
How do I fix CVE-2025-1402?
To fix CVE-2025-1402, update the Event Tickets and Registration plugin to version 5.19.1.2 or later.
Who is affected by CVE-2025-1402?
Users of the Event Tickets and Registration plugin for WordPress up to version 5.19.1.1 are affected by CVE-2025-1402.
What causes CVE-2025-1402?
CVE-2025-1402 is caused by a missing capability check on the 'ajax_ticket_delete' function.
Can authenticated users exploit CVE-2025-1402?
Yes, authenticated attackers with Contribut… role can exploit CVE-2025-1402 to delete tickets without permission.