Missing Authorization Vulnerability in Liquid Web Event Tickets Plugin
CVE-2026-105891
4.3MEDIUM
What is CVE-2026-105891?
A missing authorization vulnerability in Liquid Web's Event Tickets plugin allows attackers to exploit incorrectly configured access control levels. This security flaw affects versions from n/a up to 5.30.0.1, potentially enabling unauthorized access to sensitive event management functionalities. Organizations using the affected plugin should promptly review and strengthen their access control policies to mitigate risks associated with this vulnerability.
Affected Version(s)
Event Tickets 0 <= 5.30.0.1