CVE-2026-3174
Deferred Deferred - Pending Action

Unauthenticated Stripe Credential Overwrite in Event Tickets Plugin

Vulnerability report for CVE-2026-3174, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: Wordfence

Description

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant credentials (access tokens, publishable keys, and account ID), diverting all subsequent payment processing to the attacker's Stripe account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moderntribe event_tickets_and_registration to 5.27.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Event Tickets and Registration plugin for WordPress has a vulnerability where an attacker can change the site's Stripe payment settings without permission. This happens because the plugin fails to check if a user is allowed to access the Stripe OAuth return endpoint. Attackers can then replace the site's Stripe credentials with their own, redirecting all future payments to their account.

Detection Guidance

Check WordPress sites using the Event Tickets and Registration plugin versions up to 5.27.4 for unauthorized Stripe credential changes. Review server logs for suspicious OAuth return endpoint access or modifications to payment settings.

Impact Analysis

If exploited, this vulnerability allows attackers to steal all payments made through the site by diverting them to their own Stripe account. This could lead to financial losses, loss of customer trust, and potential legal issues if sensitive payment data is compromised.

Compliance Impact

This vulnerability could violate compliance with GDPR and HIPAA by exposing sensitive payment and personal data to unauthorized parties. GDPR requires protecting personal data, while HIPAA mandates secure handling of payment information. A breach could result in legal penalties and reputational damage.

Mitigation Strategies

Update the Event Tickets and Registration plugin to the latest version immediately. Rotate all Stripe credentials (access tokens, publishable keys, account ID) and review payment settings for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-3174. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart