CVE-2026-14819: Event Tickets < 5.28.4 - Editor+ Stored XSS via Ticket Move
The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Event Tickets and Registration WordPress pluginto a version that resolves this vulnerability.Fixed in 5.28.4 - Operational
Update the Event Tickets and Registration WordPress plugin to 5.28.4 or later to address the Stored XSS in the ticket history log where event titles were not properly escaped.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14819?
CVE-2026-14819 has a risk score of 40, indicating a moderate level of severity.
How do I fix CVE-2026-14819?
To mitigate CVE-2026-14819, upgrade the Event Tickets and Registration WordPress plugin to version 5.28.4 or later.
Who is affected by CVE-2026-14819?
CVE-2026-14819 affects users with the Editor role and above on multi-site installations using the vulnerable version of the plugin.
What type of vulnerability is CVE-2026-14819?
CVE-2026-14819 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
What impact does CVE-2026-14819 have on users?
CVE-2026-14819 allows attackers to execute malicious scripts against higher-privileged users in the ticket history log.