Missing Authorization Vulnerability in WP Swings Event Tickets Manager for WooCommerce
CVE-2026-57400

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 July 2026

What is CVE-2026-57400?

A missing authorization vulnerability in the WP Swings Event Tickets Manager for WooCommerce allows unauthorized users to exploit improperly configured access controls. This can lead to potential unauthorized access or modification of event ticket data, affecting user privacy and system integrity. The vulnerability affects versions of the plugin from an unlisted version up to 1.5.5, emphasizing the need for timely updates and security assessments to safeguard against exploitation.

Affected Version(s)

Event Tickets Manager for WooCommerce 0 <= 1.5.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

okndjo | Patchstack Bug Bounty Program
.