CVE-2025-1762: Event Tickets with Ticket Scanner < 2.5.4 - Arbitrary Tickets Deletion via CSRF
The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1762?
CVE-2025-1762 is considered a moderate severity vulnerability due to the potential for CSRF attacks affecting admin settings.
How do I fix CVE-2025-1762?
To fix CVE-2025-1762, update the Event Tickets with Ticket Scanner plugin to version 2.5.4 or later.
What causes CVE-2025-1762?
CVE-2025-1762 is caused by the lack of CSRF checks when updating settings in the affected WordPress plugin.
Who is affected by CVE-2025-1762?
Users of the Event Tickets with Ticket Scanner WordPress plugin prior to version 2.5.4 are affected by CVE-2025-1762.
What type of attack is facilitated by CVE-2025-1762?
CVE-2025-1762 facilitates Cross-Site Request Forgery (CSRF) attacks that can allow unauthorized changes by attackers.