Extension WordPress
Vulnérabilités Event Tickets with Ticket Scanner
Cette page rassemble les failles publiées pour Event Tickets with Ticket Scanner, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Event Tickets with Ticket Scanner
7 fiches
Event Tickets with Ticket Scanner <= 2.8.5 – Unauthenticated Remote Code Execution
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.8.5. This makes it possible for unauthenticated attackers to execute code on the server.
*-2.8.5
2.8.6
15/01/2026
Event Tickets with Ticket Scanner <= 2.5.3 – Cross-Site Request Forgery to Arbitrary Ticket Deletion
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.3. This is due to missing or incorrect nonce validation on the executeJSON() function. This makes…
*-2.5.3
2.5.4
06/03/2025
Event Tickets with Ticket Scanner <= 2.4.4 – Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping and missing authorization…
*-2.4.3
2.4.4
05/12/2024
Event Tickets with Ticket Scanner <= 2.3.11 – Authenticated (Author+) Remote Code Execution
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.3.11. This makes it possible for authenticated attackers, with author-level access and above, to execute code…
*-2.3.11
2.3.12
15/11/2024
Event Tickets with Ticket Scanner <= 2.3.7 – Authenticated (Admin+) Stored Cross-Site Scripting
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.3.7 due to insufficient input sanitization and output escaping. This makes it possible…
*-2.3.7
2.3.8
13/08/2024
Event Tickets with Ticket Scanner <= 2.3.1 – Reflected Cross-Site Scripting
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-2.3.1
2.3.2
03/06/2024
Event Tickets with Ticket Scanner <= 1.5.4 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.4 via the 'data[codes]' parameter saved through the 'sasoEventtickets_executeAdminSettings' AJAX action, due to insufficient input sanitization and…
[*, 1.5.5)
1.5.5
18/08/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.