Sceawere

Vulnerability Detail

CVE-2026-105888UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Event Tickets Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
4h ago
Vendor
Liquid Web / StellarWP
Product
Event Tickets
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0.1.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-08T13:17:13.790Z",
  "pubdate": "2026-10-08T13:17:13.790Z",
  "executiveSummary": "The Event Tickets plugin by Liquid Web/StellarWP is susceptible to a Missing Authorization vulnerability. This security flaw stems from improperly configured access control security levels, which fail to adequately validate user permissions during specific operations.\nThe vulnerability affects Event Tickets versions from n/a through 5.30.0.1. By exploiting this flaw, an attacker can perform unauthorized actions within the plugin's ecosystem that should otherwise be restricted to higher-privileged accounts or administrators.\nThe risk implication is significant as it potentially allows for unauthorized data manipulation, configuration changes, or access to sensitive event information depending on the specific endpoints exposed without authorization checks.\nExploitation does not require elevated administrative privileges, as the primary issue is the lack of server-side capability verification. This allows unauthenticated or low-privileged users to interact with functionality that lacks the necessary authorization hooks. Successful exploitation could lead to integrity loss, unauthorized exposure of event data, or potential disruption of event management workflows within the WordPress environment.\nOrganizations using this plugin are advised to verify their current version and monitor for official vendor updates to address the underlying access control logic failures.",
  "technicalDetails": "The core of this vulnerability lies in the improper implementation of authorization checks within the Event Tickets plugin's request handling architecture. Specifically, certain administrative or sensitive functions within the plugin fail to verify the current user's capabilities or roles before executing requested operations. In WordPress plugin development, this typically manifests when functions hooked into 'admin-ajax.php' or REST API endpoints do not explicitly call 'current_user_can()' or similar authorization primitives.\nThe attack flow initiates when a user sends a crafted HTTP request to a vulnerable endpoint. Because the plugin relies on client-side security levels or assumes legitimate intent without verifying the session's privilege level, the server-side code proceeds to process the request despite the user lacking the requisite permissions. This constitutes a Missing Authorization vulnerability, often categorized under CWE-862 (Missing Authorization).\nIn the context of Event Tickets (versions 5.30.0.1 and earlier), this allows an attacker to manipulate event data or invoke backend functions that are intended for restricted use. An attacker can perform reconnaissance on the plugin's REST API or AJAX handlers to identify endpoints that perform state-changing operations (such as deleting tickets, modifying attendee records, or altering configuration settings) without verifying the caller's session permissions.\nTechnical exploitation typically involves identifying the specific action names or API routes exposed by the plugin. Once identified, an attacker can craft a request, potentially using standard tools like 'curl' or browser developer tools, to trigger the vulnerable function. Since the application fails to validate the user's role against the required capability level (e.g., 'manage_options' or 'edit_posts'), the application executes the logic as if requested by an authorized administrator. This bypasses the intended security boundary of the WordPress user management system.\nThe post-exploitation impact is contingent upon the functions reachable through the unauthorized endpoint. If the affected component manages database writes, an attacker could potentially inject malicious event details, corrupt ticket inventories, or leak participant data. Because the access control failure occurs at the application logic layer, the plugin effectively acts as a proxy for the attacker's commands, granting them illicit control over the ticket management features without requiring prior authentication or administrative privileges."
}
CVE-2026-105888: Event Tickets Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 5.4) | Sceawere