Vulnerabilities / Event Tickets and Registration / WPSEC-2026-0522
Event Tickets and Registration <= 5.30.0.1 - Unauthenticated Payment Bypass via RSVP Order REST Endpoint
Medium 5.3
CWE-840Fixed in 5.30.0.2
- ID
- WPSEC-2026-0522
- Plugin
- Event Tickets and Registration (event-tickets)
- Affected
- from 5.30.0 before 5.30.0.2
- Remediation
- Update to 5.30.0.2 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-840
- Usage
- Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- Event Tickets and Registration on WPSec AttackSurface
- Fix released
- Published
Description
The Event Tickets and Registration plugin for WordPress is vulnerable to a payment bypass in versions 5.30.0 to 5.30.0.1 via the RSVP order REST endpoint. The publicly accessible endpoint accepts any Tickets Commerce ticket ID without verifying that the ticket is an RSVP, and does not reject carts whose total is above zero; the order is then created on the free gateway and marked as completed. This makes it possible for unauthenticated attackers to obtain completed orders and attendee records (admission tickets) for paid Tickets Commerce tickets without paying.
References
- https://wpsec.com/vuln/WPSEC-2026-0522/
- https://plugins.svn.wordpress.org/event-tickets/tags/5.30.0.2/
- https://wordpress.org/plugins/event-tickets/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS