Missing Authorization Vulnerability in Nexcess Event Tickets Plugin
CVE-2026-57705
7.5HIGH
What is CVE-2026-57705?
The Nexcess Event Tickets plugin for WordPress contains a missing authorization vulnerability that enables attackers to exploit incorrectly configured access control levels. This flaw affects versions of the plugin from n/a to 5.28.5, potentially allowing unauthorized users to gain access to restricted functionalities. Website administrators are advised to update their plugins to mitigate the risk of exploitation.
Affected Version(s)
Event Tickets 0 <= 5.28.5