Extension WordPress
Vulnérabilités Event Tickets and Registration
Cette page rassemble les failles publiées pour Event Tickets and Registration, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Event Tickets and Registration
14 fiches
Event Tickets and Registration <= 5.28.5 – Missing Authorization
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.28.5. This makes it possible for unauthenticated attackers to perform…
*-5.28.5
5.28.5.1
08/07/2026
Event Tickets and Registration <= 5.27.5 – Missing Authorization
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.27.5. This makes it possible for unauthenticated attackers to…
*-5.27.5
5.27.6.1
02/05/2026
Event Tickets and Registration <= 5.26.5 – Unauthenticated Ticket Payment Bypass
The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.26.5. This is due to the /wp-json/tribe/tickets/v1/commerce/free/order endpoint not verifying that a ticket type should be free allowing…
*-5.26.5
5.26.6
17/10/2025
Event Tickets <= 5.26.3 – Missing Authorization
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.26.3. This makes it possible for authenticated attackers, with…
*-5.26.3
5.26.4
16/10/2025
Event Tickets <= 5.20.0 – Reflected Cross-Site Scripting
The Event Tickets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.20.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-5.20.0
5.20.1
27/03/2025
Event Tickets and Registration <= 5.19.1.1 – Missing Authorization to Ticket Deletion
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function in all versions up to, and including, 5.19.1.1. This makes it possible for…
*-5.19.1.1
5.19.1.2
13/02/2025
Event Tickets <= 5.18.1 – Insecure Direct Object Reference to Sensitive Information Exposure
The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing validation on a user controlled key. This makes…
*-5.18.1
5.18.1.1
29/01/2025
Event Tickets <= 5.11.0.4 – Cross-Site Request Forgery
The Event Tickets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.11.0.4. This is due to missing or incorrect nonce validation on the handle_action_disconnect() function. This makes it possible for unauthenticated…
*-5.11.0.4
5.11.0.5
12/07/2024
Event Tickets and Registration <= 5.8.2 – Improper Authorization to Information Disclosure
The Event Tickets and Registration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.8.2 via the RSVP functionality. This makes it possible for authenticated attackers, with contributor access and above,…
*-5.8.2
5.8.3
26/03/2024
Event Tickets and Registration <= 5.8.1 – Missing Authorization
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it possible for…
*-5.8.1
5.8.2
21/02/2024
Event Tickets and Registration <= 5.8.0 Events Tickets Plus <= 5.9.0 – Authenticated (Contributor+) Information Exposure
The Event Tickets and Registration plugin for WordPress is vulnerable to Information Exposure in all versions up to 5.8.0 (free) & 5.9.1 (premium). This makes it possible for authenticated attackers, with contributor-level access and above, to view events…
*-5.8.0
5.8.1
08/02/2024
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 5.3.0.1)
5.3.0.1
04/03/2022
Event Tickets <= 5.2.1 – Open Redirect
The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue
*-5.2.1
5.2.2
22/12/2021
Event Tickets <= 4.10.7.1 – CSV Injection
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.
*-4.10.7.1
4.10.7.2
02/09/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.