Event Tickets and Registration <= 5.30.0.1 - Unauthenticated Payment Bypass via RSVP Order REST Endpoint

Medium 5.3 CWE-840Fixed in 5.30.0.2
ID
WPSEC-2026-0522
Plugin
Event Tickets and Registration (event-tickets)
Affected
from 5.30.0 before 5.30.0.2
Remediation
Update to 5.30.0.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-840
Usage
Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Event Tickets and Registration on WPSec AttackSurface
Fix released
Published

Description

The Event Tickets and Registration plugin for WordPress is vulnerable to a payment bypass in versions 5.30.0 to 5.30.0.1 via the RSVP order REST endpoint. The publicly accessible endpoint accepts any Tickets Commerce ticket ID without verifying that the ticket is an RSVP, and does not reject carts whose total is above zero; the order is then created on the free gateway and marked as completed. This makes it possible for unauthenticated attackers to obtain completed orders and attendee records (admission tickets) for paid Tickets Commerce tickets without paying.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0