# Event Tickets and Registration <= 5.30.0.1 - Unauthenticated Payment Bypass via RSVP Order REST Endpoint

- **ID:** WPSEC-2026-0522
- **Plugin:** Event Tickets and Registration (`event-tickets`), https://wordpress.org/plugins/event-tickets/
- **Affected versions:** from 5.30.0 before 5.30.0.2
- **Fixed in:** 5.30.0.2 (Update to 5.30.0.2 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-840
- **Usage among sites WPSec scans:** plugin Medium, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/event-tickets
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0522/

## Description

The Event Tickets and Registration plugin for WordPress is vulnerable to a payment bypass in versions 5.30.0 to 5.30.0.1 via the RSVP order REST endpoint. The publicly accessible endpoint accepts any Tickets Commerce ticket ID without verifying that the ticket is an RSVP, and does not reject carts whose total is above zero; the order is then created on the free gateway and marked as completed. This makes it possible for unauthenticated attackers to obtain completed orders and attendee records (admission tickets) for paid Tickets Commerce tickets without paying.

## References

- https://wpsec.com/vuln/WPSEC-2026-0522/
- https://plugins.svn.wordpress.org/event-tickets/tags/5.30.0.2/
- https://wordpress.org/plugins/event-tickets/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0522/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
