PT-2026-36874 · WordPress · Easy Paypal Events & Tickets

·

CVE-2026-32834

·

Published

2026-05-04

·

Updated

2026-05-04

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Easy PayPal Events & Tickets plugin for WordPress versions 1.3 and earlier
Description A hardcoded authentication bypass exists in the QR code scanning functionality. Unauthenticated remote attackers can bypass hash verification by providing 'test' as the value for the hash parameter. By accessing the 'add wpeevent button qr' endpoint, attackers can retrieve sensitive order details, including PayPal transaction IDs, customer email addresses, purchase amounts, and ticket information, provided they have a known or guessed post ID.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32834

Affected Products

Easy Paypal Events & Tickets