CVE-2025-1402

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Feb 21, 2025
Updated: Feb 25, 2025
CWE ID 862

Summary

CVE-2025-1402 is a vulnerability affecting the Event Tickets and Registration plugin for WordPress. This issue allows authenticated attackers, with Contributor-level access and above, to delete arbitrary Attendee tickets without proper capability checks on the 'ajax_ticket_delete' function. The vulnerability exists in all versions up to, and including, 5.19.1.1, potentially leading to unintended data loss for event organizers.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Event Tickets And Registration Plugin

Affected Vendors

  • WordPress