What the vulnerability does
01Description
The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view order details of orders they did not place, which includes ticket prices, user emails and order date.
Explanation of Vulnerability in Simple Terms
02Summary
Event Tickets and Registration versions up to 5.18.1 contain an access control flaw that allows unauthenticated attackers to read sensitive information over the network. The vulnerability does not require user interaction or special conditions to exploit. An attacker can retrieve limited confidential data without modifying or disrupting the site.
What an attacker can do
03Attacker Capabilities
Read sensitive information from the site without authentication.
Potential impact on your site
04Site Impact
Confidential data may be exposed to unauthenticated visitors; update the plugin immediately.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
January 30, 2025
CVE published
April 8, 2026
Record updated