๐Ÿ” CVE Alert

CVE-2025-68015

CRITICAL 9.0

WordPress Event Tickets with Ticket Scanner plugin <= 2.8.5 - Remote Code Execution (RCE) vulnerability

CVSS Score
9.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.8.5.

CWE CWE-94
Vendor vollstart
Product event tickets with ticket scanner
Published Jan 22, 2026
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for vollstart event tickets with ticket scanner

Be the first to know when new critical vulnerabilities affecting vollstart event tickets with ticket scanner are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Vollstart / Event Tickets with Ticket Scanner
0 โ‰ค 2.8.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/event-tickets-with-ticket-scanner/vulnerability/wordpress-event-tickets-with-ticket-scanner-plugin-2-7-10-remote-code-execution-rce-vulnerability?_s_id=cve

Credits

daroo | Patchstack Bug Bounty Program