The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant credentials (access tokens, publishable keys, and account ID), diverting all subsequent payment processing to the attacker's Stripe account.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Stellarwp
Stellarwp event Tickets And Registration Wordpress Wordpress wordpress |
|
| Vendors & Products |
Stellarwp
Stellarwp event Tickets And Registration Wordpress Wordpress wordpress |
Tue, 08 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant credentials (access tokens, publishable keys, and account ID), diverting all subsequent payment processing to the attacker's Stripe account. | |
| Title | Event Tickets and Registration <= 5.27.4 - Missing Authorization to Unauthenticated Stripe Credentials Update | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-09-08T11:29:59.815Z
Updated: 2026-09-09T15:58:32.668Z
Reserved: 2026-02-24T23:47:23.549Z
Link: CVE-2026-3174
Updated: 2026-09-09T15:58:22.071Z
Status : Deferred
Published: 2026-09-08T12:16:54.620
Modified: 2026-09-09T16:17:02.893
Link: CVE-2026-3174
No data.