Event Tickets with Ticket Scanner [event-tickets-with-ticket-scanner] <= 2.8.3 (unfixed)
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.8.3.
- Affected:
- up to 2.8.3
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2025-68015 on NVD →
Event Tickets with Ticket Scanner <= 2.8.5 - Unauthenticated Remote Code Execution
critical
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.8.5. This makes it possible for unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 2.8.5
- Fixed in:
- 2.8.6
- Disclosed:
- Jan 15, 2026
CVE-2025-68015 on NVD →
Event Tickets with Ticket Scanner <= 2.5.3 - Cross-Site Request Forgery to Arbitrary Ticket Deletion
medium
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.3. This is due to missing or incorrect nonce validation on the executeJSON() function. This makes it possible for unauthenticated attackers to delete arbitrary tickets via a f...
- CVSS:
- 4.3
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.4
- Disclosed:
- Mar 6, 2025
CVE-2025-1762 on NVD →
Event Tickets with Ticket Scanner [event-tickets-with-ticket-scanner] < 2.4.4
unknown
[en] The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping and missing authorization on the functionality to manage tickets. This makes it po...
- Affected:
- up to 2.4.4
- Fixed in:
- 2.4.4
- Disclosed:
- Dec 6, 2024
CVE-2024-9866 on NVD →
Event Tickets with Ticket Scanner <= 2.4.4 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping and missing authorization on the functionality to manage tickets. This makes it possibl...
- CVSS:
- 5.4
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.4
- Disclosed:
- Dec 5, 2024
CVE-2024-9866 on NVD →
Event Tickets with Ticket Scanner [event-tickets-with-ticket-scanner] < 2.3.12
unknown
[en] Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through 2.3.11.
- Affected:
- up to 2.3.12
- Fixed in:
- 2.3.12
- Disclosed:
- Nov 18, 2024
CVE-2024-52427 on NVD →
Event Tickets with Ticket Scanner <= 2.3.11 - Authenticated (Author+) Remote Code Execution
high
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.3.11. This makes it possible for authenticated attackers, with author-level access and above, to execute code on the server.
- CVSS:
- 8.8
- Affected:
- up to 2.3.11
- Fixed in:
- 2.3.12
- Disclosed:
- Nov 15, 2024
CVE-2024-52427 on NVD →
Event Tickets with Ticket Scanner <= 2.3.7 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and...
- CVSS:
- 4.4
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.8
- Disclosed:
- Aug 13, 2024
CVE-2024-6711 on NVD →
Event Tickets with Ticket Scanner [event-tickets-with-ticket-scanner] < 2.3.2
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Reflected XSS.This issue affects Event Tickets with Ticket Scanner: from n/a through 2.3.1.
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.2
- Disclosed:
- Jun 4, 2024
CVE-2024-35652 on NVD →
Event Tickets with Ticket Scanner <= 2.3.1 - Reflected Cross-Site Scripting
medium
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- CVSS:
- 6.1
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Jun 3, 2024
CVE-2024-35652 on NVD →
Event Tickets with Ticket Scanner [event-tickets-with-ticket-scanner] < 1.5.5
unknown
Update the WordPress Event Tickets with Ticket Scanner plugin to the latest available version (at least 1.5.5).
Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Event Tickets with Ticket Scanner Plugin. This could allow a malicious actor to inject malicious scripts, such as red...
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Aug 21, 2023
Event Tickets with Ticket Scanner <= 1.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.4 via the 'data[codes]' parameter saved through the 'sasoEventtickets_executeAdminSettings' AJAX action, due to insufficient input sanitization and output escaping. This makes i...
- CVSS:
- 6.4
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Aug 18, 2023
Event Tickets with Ticket Scanner [event-tickets-with-ticket-scanner] < 1.5.5
unknown
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.4 via the 'data[codes]' parameter saved through the 'sasoEventtickets_executeAdminSettings' AJAX action, due to insufficient input sanitization and output escaping. This makes i...
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Aug 18, 2023
Event Tickets with Ticket Scanner [event-tickets-with-ticket-scanner] < 2.3.8
unknown
- Affected:
- up to 2.3.8
- Fixed in:
- 2.3.8
CVE-2024-6711 on NVD →
Event Tickets with Ticket Scanner [event-tickets-with-ticket-scanner] < 2.5.4
unknown
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.4
CVE-2025-1762 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database