CVE-2025-68015: WordPress Event Tickets with Ticket Scanner plugin <= 2.8.5 - Remote Code Execution (RCE) vulnerability
Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.8.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68015?
CVE-2025-68015 has a critical severity rating of 9 according to the CVSS 3.1 metrics.
How do I fix CVE-2025-68015?
To fix CVE-2025-68015, upgrade the Vollstart Event Tickets with Ticket Scanner plugin to version 2.8.6 or later.
What type of vulnerability is CVE-2025-68015?
CVE-2025-68015 is classified as a Remote Code Execution (RCE) vulnerability caused by improper control of code generation.
Which versions of the software are affected by CVE-2025-68015?
CVE-2025-68015 affects the Vollstart Event Tickets with Ticket Scanner plugin from its initial release through version 2.8.5.
What consequences can arise from CVE-2025-68015?
Exploitation of CVE-2025-68015 can allow an attacker to execute arbitrary code on the server running the vulnerable plugin.