Vulnerabilities / Event Tickets and Registration / WPSEC-2026-0521
Event Tickets and Registration <= 5.30.0.1 - Authenticated (Subscriber+) Missing Authorization to Attendee QR Check-In Status Modification
Medium 4.3
CWE-862Fixed in 5.30.0.2
- ID
- WPSEC-2026-0521
- Plugin
- Event Tickets and Registration (event-tickets)
- Affected
- from 5.7.0 before 5.30.0.2
- Remediation
- Update to 5.30.0.2 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-862
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
- Attack surface
- Event Tickets and Registration on WPSec AttackSurface
- Fix released
- Published
Description
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data in versions 5.7.0 to 5.30.0.1 due to a missing capability check in the QR check-in admin notice, which set the '_tribe_qr_status' meta on any post ID supplied in the 'qr_checked_in' query parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to flag arbitrary attendees as already checked in by QR code by loading any admin page with a crafted parameter, causing QR code check-in to reject those attendees' tickets.
References
- https://wpsec.com/vuln/WPSEC-2026-0521/
- https://plugins.svn.wordpress.org/event-tickets/tags/5.30.0.2/
- https://wordpress.org/plugins/event-tickets/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS