๐Ÿ” CVE Alert

CVE-2026-14819

UNKNOWN 0.0

Event Tickets < 5.28.4 - Editor+ Stored XSS via Ticket Move

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations.

Vendor unknown
Product event tickets and registration
Published Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for unknown event tickets and registration

Be the first to know when new unknown vulnerabilities affecting unknown event tickets and registration are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Event Tickets and Registration
0 < 5.28.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/678a362f-b71d-4308-8fc3-f3bf3e6c3ca9/

Credits

FlashKiss WPScan