Access violation vulnerability in Event Tickets and Registration 5.18.1

The plugin called Event Tickets and Registration, used for WordPress websites, has a security issue. This problem, called Insecure Direct Object Reference, affects all versions up to and including 5.18.1. The issue is caused by not properly checking a key that is controlled by the user. This means that people who are not logged in can see information about orders that they did not make. This includes things like the prices of tickets, the email addresses of users, and the date the order was placed.

Detected in:

Event Tickets and Registration fixed vulnerable versions: >= * <= 5.18.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.