CVE-2025-30794: WordPress Event Tickets plugin <= 5.20.0 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Event Tickets event-tickets allows Reflected XSS.This issue affects Event Tickets: from n/a through <= 5.20.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30794?
CVE-2025-30794 is classified as a reflected Cross-site Scripting (XSS) vulnerability, which can allow attackers to inject malicious scripts into web pages.
How do I fix CVE-2025-30794?
To fix CVE-2025-30794, upgrade The Events Calendar Event Tickets plugin to version 5.21.0 or later.
Who is affected by CVE-2025-30794?
CVE-2025-30794 affects users of The Events Calendar Event Tickets plugin version up to and including 5.20.0.
What impact does CVE-2025-30794 have on users?
Users vulnerable to CVE-2025-30794 may be exploited through reflected XSS attacks, potentially leading to session hijacking or malware distribution.
Is CVE-2025-30794 a common vulnerability?
While reflected XSS vulnerabilities like CVE-2025-30794 are relatively common in web applications, the severity and impact can vary based on implementation and exposure.