WordPress · Event Tickets/Registration · CVE-2026-14819
**Name of the Vulnerable Software and Affected Versions**
Event Tickets and Registration WordPress plugin versions prior to 5.28.4
**Description**
Stored Cross-Site Scripting (XSS) occurs because event titles are not properly escaped before being output in a ticket history log. This allows users with the Editor role or higher to execute malicious scripts against users with higher privileges on multisite installations.
**Recommendations**
Update the plugin to version 5.28.4 or later.