{
 "id": "WPSEC-2026-0522",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0522/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0522/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0522/index.md",
 "title": "Event Tickets and Registration <= 5.30.0.1 - Unauthenticated Payment Bypass via RSVP Order REST Endpoint",
 "description": "The Event Tickets and Registration plugin for WordPress is vulnerable to a payment bypass in versions 5.30.0 to 5.30.0.1 via the RSVP order REST endpoint. The publicly accessible endpoint accepts any Tickets Commerce ticket ID without verifying that the ticket is an RSVP, and does not reject carts whose total is above zero; the order is then created on the free gateway and marked as completed. This makes it possible for unauthenticated attackers to obtain completed orders and attendee records (admission tickets) for paid Tickets Commerce tickets without paying.",
 "plugin": {
  "slug": "event-tickets",
  "name": "Event Tickets and Registration",
  "full_name": "Event Tickets and Registration",
  "wordpress_org": "https://wordpress.org/plugins/event-tickets/",
  "advisories_url": "https://wpsec.com/vuln/plugin/event-tickets/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/event-tickets"
 },
 "type": "UNKNOWN",
 "cwe": [
  "CWE-840"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "5.30.0",
    "from_inclusive": true,
    "to": "5.30.0.2",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 5.30.0 before 5.30.0.2"
  ]
 },
 "introduced_in": "5.30.0",
 "fixed_in": "5.30.0.2",
 "remediation": "Update to 5.30.0.2 or later.",
 "fix_released": "2026-10-06T11:24:26+00:00",
 "published": "2026-10-07T11:46:41+00:00",
 "updated": "2026-10-06T14:18:50.787838+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0522/",
  "https://plugins.svn.wordpress.org/event-tickets/tags/5.30.0.2/",
  "https://wordpress.org/plugins/event-tickets/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/event-tickets",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}