Back to overview

CVE-2026-14819

LOW Exploitation: PoC
3.5
CVSS 3.1
Description
The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations.

Metadata

CVE ID
CVE-2026-14819
State
PUBLISHED
Assigner
WPScan
Reserved
2026-07-06 08:27 UTC
Published
2026-07-28 06:00 UTC
Last updated
2026-07-28 13:25 UTC
Primary CWE
CWE-79
CWE-79 Improper Neutralization of Input During Web Page Gene…
Vendor / Product
Unknown / Event Tickets and Registration
Sources
cve.org  ·  NVD

Severity & Metrics

3.5 LOW CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Unknown Event Tickets and Registration 0 < 5.28.4
Weakness (CWE)
CWESourceDescription
cna CWE-79 Cross-Site Scripting (XSS)
CWE-79 adp CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS scores (1)
ScoreSeverityVersionSourceVector
3.5 LOW 3.1 adp CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Back to overview