plugin

Event Tickets With Ticket Scanner Vulnerabilities

15 known security issues reported for the Event Tickets With Ticket Scanner WordPress plugin. Most recent disclosed Jan 22, 2026.

1 critical 1 high 5 medium

Running Event Tickets With Ticket Scanner on your site? Check whether your installed version is affected.

Scan your site free

Event Tickets with Ticket Scanner [event-tickets-with-ticket-scanner] <= 2.8.3 (unfixed)

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.8.3.

Affected:
up to 2.8.3
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-68015 on NVD →

Event Tickets with Ticket Scanner <= 2.8.5 - Unauthenticated Remote Code Execution

critical

The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.8.5. This makes it possible for unauthenticated attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 2.8.5
Fixed in:
2.8.6
Disclosed:
Jan 15, 2026

CVE-2025-68015 on NVD →

Event Tickets with Ticket Scanner <= 2.5.3 - Cross-Site Request Forgery to Arbitrary Ticket Deletion

medium

The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.3. This is due to missing or incorrect nonce validation on the executeJSON() function. This makes it possible for unauthenticated attackers to delete arbitrary tickets via a f...

CVSS:
4.3
Affected:
up to 2.5.3
Fixed in:
2.5.4
Disclosed:
Mar 6, 2025

CVE-2025-1762 on NVD →

Event Tickets with Ticket Scanner [event-tickets-with-ticket-scanner] < 2.4.4

unknown

[en] The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping and missing authorization on the functionality to manage tickets. This makes it po...

Affected:
up to 2.4.4
Fixed in:
2.4.4
Disclosed:
Dec 6, 2024

CVE-2024-9866 on NVD →

Event Tickets with Ticket Scanner <= 2.4.4 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping and missing authorization on the functionality to manage tickets. This makes it possibl...

CVSS:
5.4
Affected:
up to 2.4.3
Fixed in:
2.4.4
Disclosed:
Dec 5, 2024

CVE-2024-9866 on NVD →

Event Tickets with Ticket Scanner [event-tickets-with-ticket-scanner] < 2.3.12

unknown

[en] Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through 2.3.11.

Affected:
up to 2.3.12
Fixed in:
2.3.12
Disclosed:
Nov 18, 2024

CVE-2024-52427 on NVD →

Event Tickets with Ticket Scanner <= 2.3.11 - Authenticated (Author+) Remote Code Execution

high

The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.3.11. This makes it possible for authenticated attackers, with author-level access and above, to execute code on the server.

CVSS:
8.8
Affected:
up to 2.3.11
Fixed in:
2.3.12
Disclosed:
Nov 15, 2024

CVE-2024-52427 on NVD →

Event Tickets with Ticket Scanner <= 2.3.7 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and...

CVSS:
4.4
Affected:
up to 2.3.7
Fixed in:
2.3.8
Disclosed:
Aug 13, 2024

CVE-2024-6711 on NVD →

Event Tickets with Ticket Scanner [event-tickets-with-ticket-scanner] < 2.3.2

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Reflected XSS.This issue affects Event Tickets with Ticket Scanner: from n/a through 2.3.1.

Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
Jun 4, 2024

CVE-2024-35652 on NVD →

Event Tickets with Ticket Scanner <= 2.3.1 - Reflected Cross-Site Scripting

medium

The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

CVSS:
6.1
Affected:
up to 2.3.1
Fixed in:
2.3.2
Disclosed:
Jun 3, 2024

CVE-2024-35652 on NVD →

Event Tickets with Ticket Scanner [event-tickets-with-ticket-scanner] < 1.5.5

unknown

Update the WordPress Event Tickets with Ticket Scanner plugin to the latest available version (at least 1.5.5). Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Event Tickets with Ticket Scanner Plugin. This could allow a malicious actor to inject malicious scripts, such as red...

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Aug 21, 2023

Event Tickets with Ticket Scanner <= 1.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.4 via the 'data[codes]' parameter saved through the 'sasoEventtickets_executeAdminSettings' AJAX action, due to insufficient input sanitization and output escaping. This makes i...

CVSS:
6.4
Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Aug 18, 2023

Event Tickets with Ticket Scanner [event-tickets-with-ticket-scanner] < 1.5.5

unknown

The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.4 via the 'data[codes]' parameter saved through the 'sasoEventtickets_executeAdminSettings' AJAX action, due to insufficient input sanitization and output escaping. This makes i...

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Aug 18, 2023

Event Tickets with Ticket Scanner [event-tickets-with-ticket-scanner] < 2.3.8

unknown
Affected:
up to 2.3.8
Fixed in:
2.3.8

CVE-2024-6711 on NVD →

Event Tickets with Ticket Scanner [event-tickets-with-ticket-scanner] < 2.5.4

unknown
Affected:
up to 2.5.4
Fixed in:
2.5.4

CVE-2025-1762 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database