SQL Injection Vulnerability in Event Tickets Plugin by Modern Tribe
CVE-2026-97287

8.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
30 September 2026

What is CVE-2026-97287?

The Event Tickets plugin by Modern Tribe contains a vulnerability that allows attackers to execute SQL injection attacks, potentially compromising the database integrity. This can lead to unauthorized access to sensitive information, manipulation of existing data, or even complete control over the site's database. Users are advised to update their plugins to the latest version to mitigate these security risks.

Affected Version(s)

Event Tickets <= 5.29.5

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Intrudify | Patchstack Bug Bounty Program
.