high · CVSS v3 8.5
CVE-2026-97287
A SQL injection vulnerability exists in the Contributor module of Event Tickets plugin versions up to 5.29.5. Attackers can inject arbitrary
Overview
A SQL injection vulnerability exists in the Contributor module of Event Tickets plugin versions up to 5.29.5. Attackers can inject arbitrary SQL via unfiltered input, potentially compromising the database. This flaw can lead to data exposure or modification.
Description
Contributor SQL Injection in Event Tickets <= 5.29.5 versions.
Impact
Confidentiality: attackers can read sensitive data. Integrity: can modify or delete records. Availability: may cause database errors. Impacted: WordPress site owners using Event Tickets plugin, especially those with contributor roles.
Remediation
Update Event Tickets to 5.29.6 or later. If update is not possible, disable contributor functionality or restrict contributor role. Ensure database credentials have least privilege.
Risk context
High severity (CVSS 8.5). Immediate attention recommended.
Affected products
- Event Tickets <=5.29.5
- Modern Tribe Event Tickets
- WordPress Event Tickets plugin
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 8.5
- CVSS v4
- —
- EPSS
- —