← Volver al buscador de CVEs

CVE-2026-32834

Easy PayPal Events & Tickets

Descripción

Easy PayPal Events & Tickets plugin for WordPress version 1.3 and earlier contain a hardcoded authentication bypass vulnerability in the QR code scanning functionality that allows unauthenticated remote attackers to bypass hash verification by supplying -test- as the hash parameter. Attackers can access the vulnerable endpoint via the add_wpeevent_button_qr action to retrieve sensitive order details including PayPal transaction IDs, customer email addresses, purchase amounts, and ticket information for any order with a known or guessed post ID. This plugin was officially closed as of 2026-03-18.

CVSS 7.5EPSS 0.44799999999999995%Riesgo 0.78
Ver fuente
Publicación
2026-05-04 18:16:27
Versiones afectadas
<=1.3
Tipo
Installed app
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N