CVE-2026-105893: WordPress Event Tickets plugin <= 5.30.0.1 - Broken Access Control vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Manipulating User-Controlled Variables.This issue affects Event Tickets: from n/a through 5.30.0.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Event Tickets pluginto a version that resolves this vulnerability.Fixed in 5.30.0.2
Event History
Frequently Asked Questions
Who can exploit this issue?
The listed CVSS vector indicates that it can be exploited remotely over the network without authentication or user interaction. The impact is limited to integrity, with no stated confidentiality or availability impact.
Which Event Tickets versions are affected?
Event Tickets versions through 5.30.0.1 are affected. The available data does not identify a fixed version.
What is the vulnerability's likely security impact?
The issue is an authorization bypass involving user-controlled variables or keys, allowing manipulation of user-controlled variables. The provided scoring indicates a low integrity impact.