Sceawere
Vulnerability Detail
CVE-2026-104675UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Event Tickets Missing Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 10h ago
- Vendor
- Liquid Web / StellarWP
- Product
- Event Tickets
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-05T09:17:09.030Z",
"pubdate": "2026-10-05T09:17:09.030Z",
"executiveSummary": "A Missing Authorization vulnerability has been identified in the Liquid Web / StellarWP Event Tickets plugin, affecting all versions from n/a through 5.30.0.\nThe vulnerability originates from an incorrectly configured access control mechanism within the application's security architecture.\nThis flaw allows unauthorized users to perform sensitive actions or access restricted data that should otherwise be protected by specific privilege requirements.\nThe impact involves a breach of the principle of least privilege, potentially allowing authenticated or unauthenticated attackers to manipulate event data or perform unauthorized operations.\nThe risk implication is significant as it exposes the administrative or management functionality of the Event Tickets plugin to unauthorized parties.\nExploitation does not necessarily require advanced knowledge but relies on the failure of the application to enforce adequate server-side authorization checks for user requests.\nOrganizations using the affected software are at risk of data integrity compromise and unauthorized state changes within their WordPress event management ecosystem.",
"technicalDetails": "The vulnerability is rooted in an improper authorization check implementation within the Liquid Web / StellarWP Event Tickets plugin's request handling logic.\nSpecifically, the plugin fails to perform adequate access control validation when processing requests directed at its backend administrative or management functionality.\nIn a secure environment, functions governing event configuration, participant data, or system settings must verify the user's session token or capability level before executing the requested action.\nIn the vulnerable versions (n/a through 5.30.0), the application fails to perform these essential capability checks, allowing an attacker to bypass intended restrictions.\nThe attack flow typically involves an attacker identifying the specific API endpoint or action hook responsible for the unauthorized functionality.\nOnce identified, the attacker crafts a malicious HTTP request (typically a POST or GET request) targeting the specific function.\nBecause the application logic does not validate the security level of the requesting user, the server processes the request as if it originated from a highly privileged user.\nThis lack of authorization manifests as a breakdown in the access control layer, permitting unauthorized actors to execute protected functions, modify database entries, or manipulate event tickets without the required administrative permissions.\nThe scope of impact is restricted by the specific functions the vulnerability exposes, but in the context of event management, this often involves the manipulation of ticket data, customer information, or plugin configurations.\nSince the vulnerability pertains to authorization rather than authentication, the attacker may interact with these endpoints without the need for credentials, or by using a low-privilege account to perform actions reserved for administrators.\nPost-exploitation, the attacker could potentially alter event details, extract sensitive ticket information, or disrupt the availability of ticketing services through unauthorized state changes.\nThe vulnerability is persistent across the specified range, indicating a global weakness in the plugin's architectural approach to authorization controls rather than an isolated bug in a single function."
}