CVE-2026-7421 PUBLISHED

Passeum Ticketing <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'shop_name' Setting

Assigner: Wordfence
Reserved: 29.04.2026 Published: 02.06.2026 Updated: 03.06.2026

The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0. This is due to the get_shop_url() method returning the shop_name setting value without sanitization when it begins with "http", combined with insufficient validation in the validate_shop_name() function which only checks for empty values and string type. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary external scripts by setting the shop_name to an attacker-controlled URL (e.g., https://attacker.com), which causes the plugin to enqueue external JavaScript and CSS from the attacker-controlled domain via wp_register_script() and wp_register_style(). The injected scripts execute on every frontend page containing any Passeum Ticketing shortcode, affecting all site visitors. Please note that this does not affect single-site installations as administrators already have the unfiltered_html capability.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
CVSS Score: 4.4

Product Status

Vendor passeum
Product Passeum Ticketing
Versions Default: unaffected
  • affected from 0 to 1.0 (incl.)

Credits

  • KEVIN LEE finder

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE