CVE-2026-14822: Unknown Event Tickets And Registration

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders.

Affected products

  • Unknown Event Tickets And Registration: before 5.29.0.1 (fixed in 5.29.0.1)

Published 2026-08-01. Last modified 2026-08-26.