CyberRota Analysis
AI-GeneratedThe Event Tickets and Registration plugin for WordPress is vulnerable due to a lack of capability checks on the Stripe OAuth return endpoint, allowing unauthenticated attackers to modify critical payment processing credentials. This vulnerability can lead to unauthorized access to the site's Stripe merchant account, enabling attackers to reroute payments to their own accounts. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of financial fraud and data compromise.
Original NVD Description
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant credentials (access tokens, publishable keys, and account ID), diverting all subsequent payment processing to the attacker's Stripe account.