CVE-2026-14823: Event Tickets < 5.29.0.1 - Contributor+ Seating Layout and Ticket Inventory Modification via IDOR
Published Aug 1, 2026
·Updated
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of events they do not own.
Affected Software
1 affected component
WordPress Event Tickets<5.29.0.1
Event History
Aug 1, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-14823?
The severity of CVE-2026-14823 is rated at a risk level of 52.
2
How do I fix CVE-2026-14823?
To fix CVE-2026-14823, update the Event Tickets plugin to version 5.29.0.1 or later.
3
What type of vulnerability is CVE-2026-14823?
CVE-2026-14823 is an IDOR (insecure direct object reference) vulnerability.
4
Who is affected by CVE-2026-14823?
Any user with contributor-level access or higher is affected by CVE-2026-14823.
5
What can attackers do with CVE-2026-14823?
Attackers can overwrite seating layouts, modify ticket inventory, and change attendee seat assignments for events they do not own.