SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-3174

HIGH · CVSS 7.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Event Tickets and Registration plugin for WordPress is vulnerable due to a lack of capability checks on the Stripe OAuth return endpoint, allowing unauthenticated attackers to modify critical payment processing credentials. This vulnerability can lead to unauthorized access to the site's Stripe merchant account, enabling attackers to reroute payments to their own accounts. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of financial fraud and data compromise.

CVE
CVE-2026-3174
Severity
HIGH
CVSS
7.5
EPSS
0.26%
WordPress

Original NVD Description

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant credentials (access tokens, publishable keys, and account ID), diverting all subsequent payment processing to the attacker's Stripe account.