PatchSiren cyber security CVE debrief
CVE-2026-14822 Event Tickets and Registration CVE debrief
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders. This vulnerability could lead to unauthorized changes in order status, potentially impacting the integrity of event ticket sales and registrations. The CVE record and NVD detail indicate that defenders should verify plugin version and endpoint access controls. Additional information may be needed to fully understand the vulnerability's impact and to confirm affected systems. Defenders should review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Vendor
- Event Tickets and Registration
- Product
- Event Tickets and Registration WordPress plugin
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-01
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-01
- Advisory updated
- 2026-08-26
Who should care
Users of the Event Tickets and Registration WordPress plugin, particularly those responsible for managing event tickets and registrations, should be aware of this vulnerability. They should assess their exposure, apply patches or mitigations, and monitor for potential unauthorized changes to order statuses.
Technical summary
The Event Tickets and Registration WordPress plugin before 5.29.0.1 lacks authorization checks on an order-management REST endpoint, allowing unauthenticated users to modify order status. This could lead to unauthorized changes in order status, potentially impacting the integrity of event ticket sales and registrations.
Defensive priority
Patch and verify plugin version; restrict endpoint access
Recommended defensive actions
- Patch the Event Tickets and Registration WordPress plugin to version 5.29.0.1 or later
- Verify and restrict access to the affected order-management REST endpoint
- Monitor for unauthorized order status changes
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The evidence for this CVE is limited. The CVE record and NVD detail indicate that the Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders. Defenders should verify plugin version and endpoint access controls. Additional information may be needed to fully understand the vulnerability's impact and to confirm affected systems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-14822 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-14822
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-14822 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14822
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/ec32cf58-9fc0-4817-8492-92d80be74ef4/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.