CVE-2026-14822 PUBLISHED

Event Tickets < 5.29.0.1 - Unauthenticated PayPal Order Status Manipulation

Assigner: WPScan
Reserved: 06.07.2026 Published: 01.08.2026 Updated: 01.08.2026

The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders.

Product Status

Vendor Unknown
Product Event Tickets and Registration
Versions Default: unaffected
  • affected from 0 to 5.29.0.1 (excl.)

Credits

  • Minar finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE