PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14822 Event Tickets and Registration CVE debrief

The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders. This vulnerability could lead to unauthorized changes in order status, potentially impacting the integrity of event ticket sales and registrations. The CVE record and NVD detail indicate that defenders should verify plugin version and endpoint access controls. Additional information may be needed to fully understand the vulnerability's impact and to confirm affected systems. Defenders should review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review.

Vendor
Event Tickets and Registration
Product
Event Tickets and Registration WordPress plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-01
Original CVE updated
2026-08-01
Advisory published
2026-08-01
Advisory updated
2026-08-01

Who should care

Users of the Event Tickets and Registration WordPress plugin, particularly those responsible for managing event tickets and registrations, should be aware of this vulnerability. They should assess their exposure, apply patches or mitigations, and monitor for potential unauthorized changes to order statuses.

Technical summary

The Event Tickets and Registration WordPress plugin before 5.29.0.1 lacks authorization checks on an order-management REST endpoint, allowing unauthenticated users to modify order status. This could lead to unauthorized changes in order status, potentially impacting the integrity of event ticket sales and registrations.

Defensive priority

Patch and verify plugin version; restrict endpoint access

Recommended defensive actions

  • Patch the Event Tickets and Registration WordPress plugin to version 5.29.0.1 or later
  • Verify and restrict access to the affected order-management REST endpoint
  • Monitor for unauthorized order status changes
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The evidence for this CVE is limited. The CVE record and NVD detail indicate that the Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders. Defenders should verify plugin version and endpoint access controls. Additional information may be needed to fully understand the vulnerability's impact and to confirm affected systems.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T07:16:30.623Z and has not been modified since then.