What is CVE-2026-14823?
This vulnerability exists in the Event Tickets and Registration WordPress plugin before version 5.29.0.1. The plugin does not properly verify authorization on some seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of events they do not own.
Azərbaycanca: Bu zəiflik 5.29.0.1-dən əvvəlki Event Tickets and Registration WordPress plaginində aşkarlanıb. Plagin bəzi oturma planı (seating) əməliyyatlarında icazə yoxlamasını düzgün aparmır, nəticədə 'Contributor' və daha yuxarı səviyyəli istifadəçilər özlərinə aid olmayan tədbirlərin oturma planını, bilet inventarını və iştirakçı yerlərini üzərinə yaza bilir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which user roles are affected by the CVE-2026-14823 vulnerability in the Event Tickets and Registration plugin?
This vulnerability affects users with contributor-level access and above. Users with these roles can overwrite the seating layout, ticket inventory, and attendee seat assignments of events they do not own.
To mitigate CVE-2026-14823, to which version should the Event Tickets and Registration plugin be updated?
This vulnerability exists in all versions before 5.29.0.1. To mitigate the vulnerability, the plugin should be updated to version 5.29.0.1 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.