What is CVE-2026-14819?
This is a Stored XSS vulnerability found in the Event Tickets and Registration WordPress plugin before version 5.28.4. Due to improper escaping of event titles in the ticket history log, users with Editor role or higher can execute scripts that target higher-privileged users in multisite installations. To mitigate this, immediately update the plugin to version 5.28.4 or later.
Azərbaycanca: Bu, WordPress-in Event Tickets and Registration plaginində aşkarlanan Stored XSS zəifliyidir. Plagin 5.28.4 versiyasından əvvəl tədbir başlıqlarını ticket history log-da düzgün escape etmədiyi üçün, Editor və ya daha yüksək roluna malik istifadəçilər multisayt şəraitində daha yuxarı səlahiyyətli istifadəçiləri hədəfləyən skript hücumları həyata keçirə bilərlər. Zəifliyin aradan qaldırılması üçün plagini dərhal 5.28.4 və ya daha yuxarı versiyaya yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin users are affected by the CVE-2026-14819 vulnerability?
This vulnerability affects sites using the Event Tickets and Registration plugin versions prior to 5.28.4.
What is the minimum user role required to exploit the CVE-2026-14819 Stored XSS vulnerability?
The attacker must have at least an Editor role or higher in a WordPress multisite environment.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.