CVE-2026-104675: WordPress Event Tickets plugin <= 5.30.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Event Tickets pluginto a version that resolves this vulnerability.Fixed in 5.30.0.1
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs low-level privileges. No user interaction is required, and the issue can be exploited over the network.
What is the likely impact if exploited?
The reported impact is limited to integrity: an attacker may be able to make unauthorized changes. The supplied CVSS vector reports no confidentiality or availability impact.
Which Event Tickets versions are affected?
The affected range is reported as Event Tickets versions through 5.30.0. No fixed version is provided in the available data.