CVE-2026-14822: Unknown Event Tickets And Registration
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders.
Affected products
- Unknown Event Tickets And Registration: before 5.29.0.1 (fixed in 5.29.0.1)
Published 2026-08-01. Last modified 2026-08-26.