CVE-2026-14822

The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-01 07:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-14822

Mitre link : CVE-2026-14822

CVE.ORG link : CVE-2026-14822


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control