Back to CVE List

CVE-2026-14819

Vulnerability Description

The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
Event Tickets and Registration

External References

Discussion (0)

Add Comment

No comments yet. Be the first!