CVE-2026-105888: WordPress Event Tickets plugin <= 5.30.0.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Event Tickets pluginto a version that resolves this vulnerability.Fixed in 5.30.0.2
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs network access and low-level privileges. No user interaction is required, and the attack complexity is rated low.
What is the expected impact if exploitation succeeds?
The reported impact is limited confidentiality and integrity impact. No availability impact is indicated.
Which installations are in scope?
Installations of Liquid Web / StellarWP Event Tickets up to and including version 5.30.0.1 are identified as affected. The available information does not state whether any particular default configuration is required.