CVE-2026-14819: CWE-79 Cross-Site Scripting (XSS) in Event Tickets and Registration
The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations.
AI Analysis
Technical Summary
The Event Tickets and Registration WordPress plugin versions prior to 5.28.4 do not properly escape event titles when displaying them in the ticket history log. This improper output encoding enables users with Editor privileges or above to perform stored Cross-Site Scripting (CWE-79) attacks. The injected scripts execute in the browsers of higher-privileged users on multisite setups, potentially leading to limited confidentiality and integrity impacts. The CVSS 3.1 base score is 3.5, reflecting low severity with network attack vector, low complexity, high privileges required, and user interaction needed.
Potential Impact
Successful exploitation allows an attacker with Editor or higher privileges to inject malicious scripts into event titles that are stored and later executed in the browsers of higher-privileged users on multisite WordPress installations. This can lead to limited confidentiality and integrity impacts such as session hijacking or unauthorized actions performed in the context of the victim user. Availability impact is not present. No known active exploitation has been reported.
Mitigation Recommendations
No official fix or patch has been confirmed or published yet. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a patch is available, restrict Editor and higher roles to trusted users only and consider monitoring or limiting input fields that accept event titles. Avoid clicking suspicious links or interacting with untrusted content in the ticket history log.
CVE-2026-14819: CWE-79 Cross-Site Scripting (XSS) in Event Tickets and Registration
Description
The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations.
CVSS v3.1
Score 3.5low
Affected software
Event Tickets and Registration
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Event Tickets and Registration WordPress plugin versions prior to 5.28.4 do not properly escape event titles when displaying them in the ticket history log. This improper output encoding enables users with Editor privileges or above to perform stored Cross-Site Scripting (CWE-79) attacks. The injected scripts execute in the browsers of higher-privileged users on multisite setups, potentially leading to limited confidentiality and integrity impacts. The CVSS 3.1 base score is 3.5, reflecting low severity with network attack vector, low complexity, high privileges required, and user interaction needed.
Potential Impact
Successful exploitation allows an attacker with Editor or higher privileges to inject malicious scripts into event titles that are stored and later executed in the browsers of higher-privileged users on multisite WordPress installations. This can lead to limited confidentiality and integrity impacts such as session hijacking or unauthorized actions performed in the context of the victim user. Availability impact is not present. No known active exploitation has been reported.
Mitigation Recommendations
No official fix or patch has been confirmed or published yet. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a patch is available, restrict Editor and higher roles to trusted users only and consider monitoring or limiting input fields that accept event titles. Avoid clicking suspicious links or interacting with untrusted content in the ticket history log.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-06T08:27:13.045Z
- State
- PUBLISHED
Threat ID: 6a684e309c2644c7f825a785
Added to database: 07/28/2026, 06:37:36 UTC
Last enriched: 07/29/2026, 23:58:42 UTC
Last updated: 09/11/2026, 22:06:31 UTC
Views: 68
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.