SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14823

LOW · CVSS 2.2 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The Event Tickets and Registration plugin for WordPress, prior to version 5.29.0.1, is vulnerable due to inadequate authorization checks, enabling users with contributor-level access or higher to manipulate seating layouts, ticket inventories, and attendee assignments for events they do not own. This flaw poses a risk of unauthorized modifications, potentially disrupting event management and attendee experiences. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-14823
Severity
LOW
CVSS
2.2
EPSS
0.15%
WordPress

Original NVD Description

The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of events they do not own.