Event Tickets and Registration <= 5.30.0.1 - Authenticated (Subscriber+) Missing Authorization to Attendee QR Check-In Status Modification

Medium 4.3 CWE-862Fixed in 5.30.0.2
ID
WPSEC-2026-0521
Plugin
Event Tickets and Registration (event-tickets)
Affected
from 5.7.0 before 5.30.0.2
Remediation
Update to 5.30.0.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-862
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
Attack surface
Event Tickets and Registration on WPSec AttackSurface
Fix released
Published

Description

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data in versions 5.7.0 to 5.30.0.1 due to a missing capability check in the QR check-in admin notice, which set the '_tribe_qr_status' meta on any post ID supplied in the 'qr_checked_in' query parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to flag arbitrary attendees as already checked in by QR code by loading any admin page with a crafted parameter, causing QR code check-in to reject those attendees' tickets.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0