rootpwn

high · CVSS v3 8.5

CVE-2026-97287

A SQL injection vulnerability exists in the Contributor module of Event Tickets plugin versions up to 5.29.5. Attackers can inject arbitrary

Overview

A SQL injection vulnerability exists in the Contributor module of Event Tickets plugin versions up to 5.29.5. Attackers can inject arbitrary SQL via unfiltered input, potentially compromising the database. This flaw can lead to data exposure or modification.

Description

Contributor SQL Injection in Event Tickets <= 5.29.5 versions.

Impact

Confidentiality: attackers can read sensitive data. Integrity: can modify or delete records. Availability: may cause database errors. Impacted: WordPress site owners using Event Tickets plugin, especially those with contributor roles.

Remediation

Update Event Tickets to 5.29.6 or later. If update is not possible, disable contributor functionality or restrict contributor role. Ensure database credentials have least privilege.

Risk context

High severity (CVSS 8.5). Immediate attention recommended.

Affected products

  • Event Tickets <=5.29.5
  • Modern Tribe Event Tickets
  • WordPress Event Tickets plugin

Scores

Severity
high
CVSS v2
7.5
CVSS v3
8.5
CVSS v4
—
EPSS
—

sql-injection wordpress event-tickets plugin high-severity database

← All CVEs