Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8550 | The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack |
Thu, 17 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vollstart
Vollstart event Tickets With Ticket Scanner |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:vollstart:event_tickets_with_ticket_scanner:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Vollstart
Vollstart event Tickets With Ticket Scanner |
Fri, 28 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 28 Mar 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Title | Event Tickets with Ticket Scanner < 2.5.4 - Arbitrary Tickets Deletion via CSRF | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-03-28T14:43:22.369Z
Reserved: 2025-02-27T16:54:35.654Z
Link: CVE-2025-1762
Updated: 2025-03-28T14:43:14.681Z
Status : Analyzed
Published: 2025-03-28T06:15:32.770
Modified: 2025-04-17T13:48:32.093
Link: CVE-2025-1762
No data.
OpenCVE Enrichment
No data.
EUVD