WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Event Tickets and Registration

Event Tickets allows your visitors to RSVP and buy tickets to events on your site. Also works seamlessly with The Events Calendar.

16Reported vulnerabilities
8.8Highest CVSS score
5.29.2.1Latest version
90,000+Active installs

What to do now

Update Event Tickets and Registration to 5.29.0.1 or later. 16 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 7, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2019-16120 High 8.8 3.2% Before 4.10.7.2 4.10.7.2 September 8, 2019
CVE-2021-25028 Medium 6.1 1.9% Before 5.2.2 5.2.2 January 24, 2022
CVE-2025-11517 High 7.5 0.4% 0 to 5.26.5 (inclusive) 5.26.6 October 18, 2025
CVE-2025-30794 Medium 6.1 0.3% 5.20.0 and earlier 5.20.1 March 27, 2025
CVE-2026-14822 Medium 5.3 0.2% Before 5.29.0.1 5.29.0.1 August 1, 2026
CVE-2026-65567 Medium 5.3 0.2% 5.29.0.1 and earlier 5.29.1 July 24, 2026
CVE-2026-57705 Medium 5.3 0.3% 5.28.5 and earlier 5.28.5.1 July 8, 2026
CVE-2026-42662 Medium 5.3 0.3% 5.27.5 and earlier 5.27.6.1 May 2, 2026
CVE-2025-1402 Medium 5.3 0.4% Before 5.19.1.2 5.19.1.2 February 21, 2025
CVE-2024-13457 Medium 5.3 0.3% 5.18.1 and earlier 5.18.1.1 January 29, 2025
CVE-2026-14823 Medium 4.3 0.1% Before 5.29.0.1 5.29.0.1 August 1, 2026
CVE-2026-14819 Medium 4.4 0.1% 5.28.3 and earlier 5.28.4 July 7, 2026
CVE-2025-62027 Medium 4.3 0.2% 5.26.3 and earlier 5.26.4 October 16, 2025
CVE-2024-38762 Medium 4.3 0.2% 5.11.0.4 and earlier 5.11.0.5 July 12, 2024
CVE-2024-2261 Medium 4.3 0.4% 5.8.2 and earlier 5.8.3 March 26, 2024
CVE-2024-1053 Medium 4.3 0.4% 0 to 5.8.1 (inclusive) 5.8.2 February 22, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.