Event Tickets and Registration WordPress Plugin Missing Authorization Vulnerability Allowing Unauthorized Ticket Deletion
Vulnerability
A vulnerability exists in the Event Tickets and Registration plugin for WordPress, affecting all versions up to and including 5.19.1.1. The issue arises from a missing capability check in the 'ajax_ticket_delete' function, which allows authenticated attackers with Contributor-level access and above to delete arbitrary Attendee tickets. This vulnerability leads to unauthorized data loss.
Impact
Exploitation of this vulnerability allows for unauthorized deletion of Attendee tickets, leading to potential disruption of event management and attendee records.
Reproduction
To reproduce this vulnerability, an authenticated user with Contributor-level access or higher can send a request to the 'ajax_ticket_delete' endpoint. The request must include the 'post_id' of the event and the 'ticket_id' of the ticket to be deleted. The absence of a proper capability check allows the deletion to occur without authorization.
Remediation
Users are advised to update the Event Tickets and Registration plugin to version 5.19.1.2 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
