The Event Tickets and Registration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.8.2 via the RSVP functionality. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including emails and street addresses.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Event Tickets and Registration <= 5.8.2 - Improper Authorization to Information Disclosure | |
| Weaknesses | CWE-639 |
Fri, 27 Feb 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:44:21.773Z
Reserved: 2024-03-07T14:11:04.433Z
Link: CVE-2024-2261
Updated: 2024-08-01T19:03:39.190Z
Status : Awaiting Analysis
Published: 2024-04-09T19:15:30.483
Modified: 2026-04-08T17:18:32.837
Link: CVE-2024-2261
No data.
OpenCVE Enrichment
No data.