The Event Tickets WordPress plugin before 5.2.2 does not validate the tribeticketsredirectto parameter before redirecting the user to the given value, leading to an arbitrary redirect issue
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.