Skip to main content

Vendor/product archive

liquidweb / event_tickets CVEs

Beta · best-effort

5 CVEs tagged to liquidweb / event_tickets0 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2024-13457

Published Jan 30, 2025

The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id paramete…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1319

Published Mar 4, 2024

The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of stat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1316

Published Mar 4, 2024

The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1053

Published Feb 22, 2024

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16120

Published Sep 8, 2019

CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1