CVE-2026-3174 HIGH

CVE-2026-3174: Event Tickets and Registration <= 5.27.4 - Missing Authorization to Unauthenticated Stripe Credentials Update

Vendor Stellarwp
Product Event Tickets and Registration
Weakness CWE-862 · Missing authorization
Published September 8, 2026
Last update September 9, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant credentials (access tokens, publishable keys, and account ID), diverting all subsequent payment processing to the attacker's Stripe account.

Key dates

02Disclosure timeline

September 8, 2026 CVE published
September 9, 2026 Record updated

Related vulnerabilities

04Related CVE