Extension WordPress

Vulnérabilités Event Tickets with Ticket Scanner

Cette page rassemble les failles publiées pour Event Tickets with Ticket Scanner, leurs plages de versions affectées et les correctifs signalés dans la base locale.

7Vulnérabilités
1Critiques
7Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Event Tickets with Ticket Scanner

7 fiches

CVE-2025-1762 Moyenne · 4,3
Event Tickets with Ticket Scanner

Event Tickets with Ticket Scanner <= 2.5.3 – Cross-Site Request Forgery to Arbitrary Ticket Deletion

The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.3. This is due to missing or incorrect nonce validation on the executeJSON() function. This makes…

Versions affectées

*-2.5.3

Correctif

2.5.4

Publication

06/03/2025

CVE-2024-9866 Moyenne · 5,4
Event Tickets with Ticket Scanner

Event Tickets with Ticket Scanner <= 2.4.4 – Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting

The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping and missing authorization…

Versions affectées

*-2.4.3

Correctif

2.4.4

Publication

05/12/2024

CVE-2024-52427 Élevée · 8,8
Event Tickets with Ticket Scanner

Event Tickets with Ticket Scanner <= 2.3.11 – Authenticated (Author+) Remote Code Execution

The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.3.11. This makes it possible for authenticated attackers, with author-level access and above, to execute code…

Versions affectées

*-2.3.11

Correctif

2.3.12

Publication

15/11/2024

CVE-2024-6711 Moyenne · 4,4
Event Tickets with Ticket Scanner

Event Tickets with Ticket Scanner <= 2.3.7 – Authenticated (Admin+) Stored Cross-Site Scripting

The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.3.7 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-2.3.7

Correctif

2.3.8

Publication

13/08/2024

CVE-2024-35652 Moyenne · 6,1
Event Tickets with Ticket Scanner

Event Tickets with Ticket Scanner <= 2.3.1 – Reflected Cross-Site Scripting

The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

Versions affectées

*-2.3.1

Correctif

2.3.2

Publication

03/06/2024

Vulnérabilité Moyenne · 6,4
Event Tickets with Ticket Scanner

Event Tickets with Ticket Scanner <= 1.5.4 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.4 via the 'data[codes]' parameter saved through the 'sasoEventtickets_executeAdminSettings' AJAX action, due to insufficient input sanitization and…

Versions affectées

[*, 1.5.5)

Correctif

1.5.5

Publication

18/08/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités