← Retour à la recherche de CVE

CVE-2026-32834

Easy PayPal Events & Tickets

Description

Easy PayPal Events & Tickets plugin for WordPress version 1.3 and earlier contain a hardcoded authentication bypass vulnerability in the QR code scanning functionality that allows unauthenticated remote attackers to bypass hash verification by supplying -test- as the hash parameter. Attackers can access the vulnerable endpoint via the add_wpeevent_button_qr action to retrieve sensitive order details including PayPal transaction IDs, customer email addresses, purchase amounts, and ticket information for any order with a known or guessed post ID. This plugin was officially closed as of 2026-03-18.

CVSS 7.5EPSS 0.44799999999999995%Risque 0.78
Voir la source
Publication
2026-05-04 18:16:27
Versions concernées
<=1.3
Type
Installed app
Vecteur
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N