GHSA-cfmh-2g6m-xpvmLowCVSS 2.2

The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify...

Published
August 1, 2026
Last Modified
August 5, 2026

🔗 CVE IDs covered (1)

📋 Description

The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of events they do not own.

🔗 References (3)