CVE-2025-68015
WordPress Event Tickets with Ticket Scanner plugin <= 2.8.5 - Remote Code Execution (RCE) vulnerability
CVSS Score
9.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.8.5.
| CWE | CWE-94 |
| Vendor | vollstart |
| Product | event tickets with ticket scanner |
| Published | Jan 22, 2026 |
| Last Updated | Apr 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for vollstart event tickets with ticket scanner
Be the first to know when new critical vulnerabilities affecting vollstart event tickets with ticket scanner are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Vollstart / Event Tickets with Ticket Scanner
0 โค 2.8.5
References
Credits
daroo | Patchstack Bug Bounty Program