CVE-2026-14822

CVE-2026-14822CVE-2026-14822

Description

The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders.

Scoring

Last modified2026-08-01
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.