CVE-2026-105891: WordPress Event Tickets plugin <= 5.30.0.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/event-ticketsto a version that resolves this vulnerability.Fixed in 5.30.0.2
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability requires low-level privileges. It is remotely exploitable and does not require user interaction.
What is the expected impact if exploitation succeeds?
The stated CVSS vector indicates integrity impact only; confidentiality and availability impacts are not indicated. The issue involves missing authorization and incorrectly configured access-control security levels.
Which versions are affected?
Event Tickets versions through 5.30.0.1 are affected. The provided data does not identify a fixed version.