CyberRota Analysis
AI-GeneratedThe Event Tickets and Registration plugin for WordPress, prior to version 5.29.0.1, is vulnerable due to inadequate authorization checks, enabling users with contributor-level access or higher to manipulate seating layouts, ticket inventories, and attendee assignments for events they do not own. This flaw poses a risk of unauthorized modifications, potentially disrupting event management and attendee experiences. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of events they do not own.