PatchSiren cyber security CVE debrief
CVE-2026-105893 Liquid Web / StellarWP CVE debrief
The CVE-2026-105893 vulnerability affects the WordPress Event Tickets plugin, specifically versions up to 5.30.0.1. This issue is related to a Broken Access Control vulnerability, which could potentially allow unauthorized access to certain features or data. The vulnerability has been categorized with a CVSS score of 5.3 and a severity of MEDIUM. Defenders responsible for WordPress installations with the Event Tickets plugin should assess exposure and apply patches or updates as necessary. The CVE record and source item provide details about the vulnerability, including its CVSS score and affected versions. However, there is limited information on potential exploits or impacts. The
- Vendor
- Liquid Web / StellarWP
- Product
- Event Tickets
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for WordPress installations with the Event Tickets plugin should assess exposure and apply patches or updates as necessary.
Why it matters
The CVE-2026-105893 vulnerability affects the WordPress Event Tickets plugin, specifically versions up to 5.30.0.1, and could potentially allow unauthorized access to certain features or data.
- Assess exposure of Event Tickets plugin versions up to 5.30.0.1
- Apply patches or updates to Event Tickets plugin versions up to 5.30.0.1
- Monitor for potential unauthorized access to Event Tickets features or data
Technical summary
The CVE-2026-105893 vulnerability is related to a Broken Access Control issue in the WordPress Event Tickets plugin, affecting versions up to 5.30.0.1. The vulnerability has a CVSS score of 5.3 and is categorized as MEDIUM severity. This issue could potentially allow unauthorized access to certain features or data. Defenders should prioritize assessing exposure and applying patches for the Event Tickets plugin, focusing on versions up to 5.30.0.1. The vulnerability
Defensive priority
Defenders should prioritize assessing exposure and applying patches for the Event Tickets plugin, focusing on versions up to 5.30.0.1.
Recommended defensive actions
- Assess exposure of Event Tickets plugin versions up to 5.30.0.1
- Apply patches or updates to Event Tickets plugin versions up to 5.30.0.1
- Monitor for potential unauthorized access to Event Tickets features or data
Evidence notes
The CVE record and source item provide details about the vulnerability, including its CVSS score and affected versions. However, there is limited information on potential exploits or impacts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105893 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105893
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105893 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105893
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
WordPress Event Tickets plugin <= 5.30.0.1 - Broken Access Control vulnerability
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105893.json
cve_program_cvelist_v5
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.