CVE-2026-14819
Event Tickets < 5.28.4 - Editor+ Stored XSS via Ticket Move
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations.
| Vendor | unknown |
| Product | event tickets and registration |
| Published | Jul 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown event tickets and registration
Be the first to know when new unknown vulnerabilities affecting unknown event tickets and registration are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Event Tickets and Registration
0 < 5.28.4
References
Credits
FlashKiss WPScan