CVE-2025-1762
The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its
The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
MEDIUM · CVSS 4.3
EPSS 0.0015
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0