CVE-2026-14819: Unknown Event Tickets And Registration
Low severity, CVSS 3.5. EPSS: 0.2% chance of exploitation in the next 30 days.
The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations.
Affected products
- Unknown Event Tickets And Registration: before 5.28.4 (fixed in 5.28.4)
Published 2026-07-28. Last modified 2026-07-28.