216.73.216.233

CVE-2025-11517

· Published 18/10/2025 07:15 · Modified 18/10/2025 07:15

Labels: CVE-2025-11517 2025-10-18CVE-2025-11517CWE-639[email protected]

Essential information

Published
18/10/2025 07:15
Modified
18/10/2025 07:15
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVSS metrics

Description

The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.26.5. This is due to the /wp-json/tribe/tickets/v1/commerce/free/order endpoint not verifying that a ticket type should be free allowing the user to bypass the payment. This makes it possible for unauthenticated attackers to obtain access to paid tickets, without paying for them, causing a loss of revenue for the target.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wordpress / event tickets and registration cpe:2.3:a:wordpress:event_tickets_and_registration:*:<5.26.6:*:*:*:wordpress:*:*

References