CVE-2026-57400: WordPress Event Tickets Manager for WooCommerce plugin <= 1.5.5 - Broken Access Control vulnerability
Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets Manager for WooCommerce: from n/a through <= 1.5.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WP Swings Event Tickets Manager for WooCommerce / Event Tickets Manager for WooCommerceto a version that resolves this vulnerability.Fixed in 1.5.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57400?
The severity of CVE-2026-57400 is medium with a score of 6.5.
How do I fix CVE-2026-57400?
To fix CVE-2026-57400, update the Event Tickets Manager for WooCommerce plugin to version 1.5.6 or later.
What kind of vulnerability is CVE-2026-57400?
CVE-2026-57400 is a Broken Access Control vulnerability affecting the Event Tickets Manager for WooCommerce.
Who is affected by CVE-2026-57400?
Users of the WP Swings Event Tickets Manager for WooCommerce plugin with versions from n/a through 1.5.5 are affected by CVE-2026-57400.
What exploitation risks are associated with CVE-2026-57400?
CVE-2026-57400 allows attackers to exploit incorrectly configured access control security levels.