Sceawere
Vulnerability Detail
CVE-2026-97634UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Event Tickets
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 15h ago
- Vendor
- stellarwp
- Product
- Event Tickets and Registration
- Attack Type
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.29.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. A Contributor-level user can reach the vulnerable code path by supplying a post_id they authored, as the can_access_page() gate requires only post authorship rather than the edit_others_posts capability for post owners.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-02T08:17:05.487Z",
"pubdate": "2026-10-02T08:17:05.487Z",
"executiveSummary": "The Event Tickets and Registration plugin for WordPress is susceptible to a SQL Injection vulnerability affecting versions 5.29.5 and prior.\nThe flaw originates from improper sanitization and lack of parameterized query usage within the 'orderby' parameter.\nThis vulnerability allows authenticated attackers with Contributor-level privileges or higher to execute arbitrary SQL commands against the backend database.\nBy manipulating the 'orderby' parameter, an attacker can bypass standard query logic to perform unauthorized data extraction, potentially leading to the compromise of sensitive information stored within the WordPress database.\nExploitation is facilitated by the plugin's authorization logic, where the 'can_access_page()' function permits users with post authorship to trigger the vulnerable code path without requiring elevated administrative privileges.\nThe risk is significant due to the potential for unauthorized data exfiltration, making it essential for users to restrict access or apply updates when available.",
"technicalDetails": "The vulnerability resides in the improper handling of the 'orderby' parameter within the Event Tickets and Registration plugin. The root cause is a combination of insufficient input validation and the omission of prepared statements during the construction of SQL queries.\nWhen a user submits a request to the vulnerable component, the 'orderby' parameter is concatenated directly into the SQL query string without adequate escaping or sanitization. This allows an attacker to break out of the intended query structure and inject malicious SQL syntax.\nThe attack flow begins when an authenticated user, holding at least Contributor-level access, interacts with a page or feature controlled by the plugin. The 'can_access_page()' function verifies authorization by checking for post authorship, which effectively bypasses the requirement for 'edit_others_posts' capabilities. Consequently, a malicious actor can craft a request targeting a post they authored to reach the vulnerable code path.\nUpon reaching the vulnerable function, the attacker includes a crafted payload within the 'orderby' parameter. Because the application fails to use parameterized queries, the database engine treats the injected SQL commands as part of the original query, executing them with the privileges of the database user account configured for the WordPress site.\nThe impact of a successful exploitation is severe, as the attacker can perform arbitrary 'SELECT' operations. This capability permits the unauthorized retrieval of sensitive data, such as user credentials, configuration details, or other proprietary information residing in the database tables. Given the nature of SQL injection, the attacker is limited primarily by the permissions of the database user; however, in many default WordPress configurations, this access is sufficient to extract substantial information.\nThis vulnerability exists in all plugin versions up to and including 5.29.5. The exposure is limited to authenticated users; however, the low bar for entry—specifically the Contributor level—increases the potential threat surface significantly in multi-author environments."
}