CVE-2026-93526: WordPress Event Tickets plugin <= 5.29.4 - Cross Site Scripting (XSS) vulnerability
Published Sep 23, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions.
Affected Software
1 affected component
WordPress Event Tickets<=5.29.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Event Tickets Pluginto a version that resolves this vulnerability.Fixed in 5.29.5
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as unauthenticated, so an attacker does not need a WordPress account or plugin privileges. Exploitation requires user interaction, as indicated by the UI:R vector.
2
Which installations are affected?
WordPress sites using Event Tickets version 5.29.4 or earlier are affected according to the available information.
3
What impact could successful exploitation have?
Successful XSS could affect confidentiality, integrity, and availability at low impact levels. The scope is changed (S:C), meaning the impact may extend beyond the vulnerable component.