---
id: CVE-2026-3174
title: >-
  The Event Tickets and Registration plugin for WordPress is vulnerable to
  unauthorized modification of data due to a missing capability check on the
  Stripe OAuth return endpoint in all versions up to, and including, 5.27.4
summary: >-
  The Event Tickets and Registration plugin for WordPress is vulnerable to
  unauthorized modification of data due to a missing capability check on the
  Stripe OAuth return endpoint in all versions up to, and including, 5.27.4.
  This makes it …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-862
vendor: stellarwp
product: Event Tickets and Registration
affected:
  - event_tickets_and_registration <= 5.27.4
published: '2026-09-08'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:17:02.893'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-3174'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/event-tickets/trunk/src/Tickets/Commerce/Gateways/Stripe/Merchant.php#L208
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/event-tickets/trunk/src/Tickets/Commerce/Gateways/Stripe/REST/Return_Endpoint.php#L50
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/changeset/3472837/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/8b13a072-f90f-4982-b4d1-d0b9903e59ea?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-09T15:58:16.578197Z'
epss: 0.00264
epssPercentile: 0.18615
ingestedAt: '2026-09-08T15:33:26.983Z'
---

## Overview

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant credentials (access tokens, publishable keys, and account ID), diverting all subsequent payment processing to the attacker's Stripe account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
