What is CVE-2026-14822?
CVE-2026-14822 is a critical vulnerability in the Event Tickets and Registration WordPress plugin versions prior to 5.29.0.1. Due to a missing authorization check on one of its order-management REST endpoints, unauthenticated users can modify the status of existing orders. Updating the plugin to version 5.29.0.1 or later is required to mitigate this issue.
Azərbaycanca: CVE-2026-14822, Event Tickets and Registration WordPress plagininin 5.29.0.1 versiyasından əvvəlki versiyalarında aşkar edilmiş kritik bir zəiflikdir. Sifariş idarəetmə REST endpoint-lərindən birində avtorizasiya yoxlamasının olmaması səbəbindən, autentifikasiya olunmamış şəxslər mövcud sifarişlərin statusunu dəyişdirə bilər. Bu zəiflikdən qorunmaq üçün plagini ən azı 5.29.0.1 versiyasına yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What does the CVE-2026-14822 vulnerability allow in the Event Tickets and Registration plugin?
This vulnerability allows unauthenticated users to modify the status of existing orders via a REST endpoint.
To which version should the Event Tickets and Registration plugin be updated to mitigate CVE-2026-14822?
The plugin must be updated to version 5.29.0.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.