{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3athe_events_calendarevent_tickets_and_registrationwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:the_events_calendar:event_tickets_and_registration:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-3174"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Event Tickets and Registration (\u003c= 5.27.4)"],"_cs_severities":["medium"],"_cs_tags":["web-application","wordpress","financial-fraud","cve-2026-3174"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eCVE-2026-3174 is a critical authorization vulnerability affecting the 'Event Tickets and Registration' plugin for WordPress in all versions up to and including 5.27.4. The vulnerability stems from a missing capability check on the Stripe OAuth return endpoint. By exploiting this flaw, an unauthenticated attacker can send crafted requests to the plugin's Stripe integration flow. Because the application fails to verify the identity of the requester, the attacker can overwrite the site's legitimate Stripe merchant credentials - specifically the Stripe access tokens, publishable keys, and account ID - with their own. Consequently, all subsequent financial transactions processed by the site will be directed to the attacker's account rather than the merchant's. This vulnerability represents a direct financial risk to organizations using the plugin to collect ticket payments, as it allows for the complete diversion of revenue without requiring administrative access to the WordPress environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to perform full financial fraud by redirecting payment traffic to arbitrary Stripe accounts. This impacts any organization using the Event Tickets and Registration plugin for commerce. Potential consequences include total loss of revenue from ticket sales, compromise of customer payment flows, and significant reputational damage.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the 'Event Tickets and Registration' plugin to a version patched against CVE-2026-3174 immediately.\u003c/li\u003e\n\u003cli\u003eAudit the WordPress 'wp_options' or equivalent plugin configuration tables for unexpected changes to Stripe account IDs, publishable keys, or API credentials.\u003c/li\u003e\n\u003cli\u003eReview recent transaction logs within the WordPress environment and Stripe dashboard for anomalies in payment routing.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-08T13:40:48Z","date_published":"2026-09-08T13:40:48Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-3174/","summary":"The Event Tickets and Registration plugin for WordPress (v5.27.4 and earlier) contains an authorization flaw in the Stripe OAuth return endpoint, allowing unauthenticated attackers to hijack site payment processing.","title":"Unauthenticated Stripe Credential Overwrite in WordPress Event Tickets Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-3174/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:the_events_calendar:event_tickets_and_registration:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}