CVE-2026-57705

WordPress Event Tickets plugin <= 5.28.5 - Broken Access Control vulnerability

Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through <= 5.28.5.


We have discovered 19,239 live websites that are affected by CVE-2026-57705.

Run a Free Instant Scan




Affected Software

Product  Event Tickets
Category Wordpress Plugins
Vulnerable Domains19,239 live websites (93% of Event Tickets install base)
Vulnerable Versions
  • from 0 through 5.28.5
Vulnerable Versions Count218 versions ( 88% of all versions)



Details

  • Published - Jul 13, 2026
  • Updated - Jul 13, 2026

Credits

  • dunvu0 | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-57705
United States9,267 websites



Germany1,999 websites
GB1,237 websites
Canada810 websites
France748 websites
Netherlands675 websites
Australia410 websites
Italy380 websites
Spain344 websites
Switzerland307 websites

Website Distribution by TLD

Number of websites using CVE-2026-57705
.com6,581 websites
.org4,601 websites
.de1,416 websites
.nl635 websites
.co.uk561 websites
.ca497 websites
.fr366 websites
.net348 websites
.org.uk285 websites
.it266 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-57705

Top websites that are affected by CVE-2026-57705. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.org United States*,***
**********.com United States*,***
***.org United States**,***
**********.com United States**,***
*****************.org United States**,***
********.app United States**,***
***********.com United States**,***
****************.org United States**,***
*************.org United States**,***
*****.org United States**,***
See full domain list

FAQ

A total of 19,239 websites have been identified as vulnerable to CVE-2026-57705, based on global website indexing conducted by WebTechSurvey.
The Event Tickets is affected by the CVE-2026-57705 vulnerability.
Event Tickets versions up to and including 5.28.5 are vulnerable to CVE-2026-57705.