Liquid Web / StellarWP Event Tickets(event-tickets)插件中存在一个通过用户控制的密钥绕过身份验证的漏洞,该漏洞允许攻击者操纵用户可控的变量。此问题影响 Event Tickets 的所有版本:从初始版本(n/a)到 5.30.0.1。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Liquid Web / StellarWP | Event Tickets | 0 ~ 5.30.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66479 | 7.1 HIGH | WordPress WPComplete plugin <= 2.9.5.6 - CSRF to Stored XSS vulnerability |
| CVE-2026-105890 | 6.5 MEDIUM | WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.12 - Cross Site Scripting (XSS) |
| CVE-2026-105888 | 5.4 MEDIUM | WordPress Event Tickets plugin <= 5.30.0.1 - Broken Access Control vulnerability |
| CVE-2026-106600 | 5.3 MEDIUM | WordPress GiveWP plugin <= 4.18.0 - Broken Access Control vulnerability |
| CVE-2026-105891 | 4.3 MEDIUM | WordPress Event Tickets plugin <= 5.30.0.1 - Broken Access Control vulnerability |
No comments yet