CVE-2026-14819

Event Tickets < 5.28.4 - Editor+ Stored XSS via Ticket Move

The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations.


We have discovered 17,420 live websites that are affected by CVE-2026-14819.

Run a Free Instant Scan




Affected Software

Product  Event Tickets
Category Wordpress Plugins
Vulnerable Domains17,420 live websites (84% of Event Tickets install base)
Vulnerable Versions
  • from 0 through 5.28.4
Vulnerable Versions Count215 versions ( 87% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 28, 2026
  • Updated - Jul 28, 2026

Credits

  • FlashKiss (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-14819
United States8,285 websites



Germany1,791 websites
GB1,106 websites
Canada731 websites
France693 websites
Netherlands624 websites
Australia368 websites
Italy355 websites
Spain328 websites
Denmark280 websites

Website Distribution by TLD

Number of websites using CVE-2026-14819
.com5,940 websites
.org4,118 websites
.de1,262 websites
.nl593 websites
.co.uk518 websites
.ca453 websites
.fr333 websites
.net300 websites
.it250 websites
.org.uk247 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-14819

Top websites that are affected by CVE-2026-14819. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.org United States*,***
**********.com United States*,***
***.org United States**,***
**********.com United States**,***
********.app United States**,***
***********.com United States**,***
****************.org United States**,***
*****.org United States**,***
*****.fr France**,***
*****************.org GB**,***
See full domain list

FAQ

CVE-2026-14819 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Event Tickets
A total of 17,420 websites have been identified as vulnerable to CVE-2026-14819, based on global website indexing conducted by WebTechSurvey.
The Event Tickets is affected by the CVE-2026-14819 vulnerability.
Event Tickets versions up to 5.28.4 are vulnerable to CVE-2026-14819.
CVE-2026-14819 is resolved in version 5.28.4 of Event Tickets.