CVE-2025-1402
MEDIUMEvent Tickets and Registration <= 5.19.1.1 - Arbitrary Attendee Ticket Deletion
Title source: llmDescription
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function in all versions up to, and including, 5.19.1.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary Attendee tickets.
References (5)
Core 5
Core References
Product
https://plugins.trac.wordpress.org/browser/event-tickets/tags/5.18.1/src/Tribe/Assets.php#L202
Product
https://plugins.trac.wordpress.org/browser/event-tickets/tags/5.18.1/src/Tribe/Metabox.php#L30
Product
https://plugins.trac.wordpress.org/browser/event-tickets/tags/5.18.1/src/Tribe/Metabox.php#L490
Permissions Required
https://wordfence.freshdesk.com/a/tickets/375051
Scores
CVSS v3
5.3
EPSS
0.0041
EPSS Percentile
32.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (2)
stellarwp/Event Tickets and Registration
< 5.19.1.1
theeventscalendar/event_tickets
< 5.19.1.2
Published
Feb 21, 2025
Tracked Since
Feb 18, 2026