Critical 9.0
2026-01-22< 2.8.6
CVE-2025-68015
Minimum safe version
2.8.6
Update to 2.8.6 or later to address 8 fixable vulnerabilities
CVE-2025-68015
Event Tickets with Ticket Scanner <= 2.5.3 - Cross-Site Request Forgery to Arbitrary Ticket Deletion
CVE-2024-9866
CVE-2024-52427
WordPress Event Tickets with Ticket Scanner Plugin < 2.3.8 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-35652
WordPress Event Tickets with Ticket Scanner Plugin < 1.5.5 is vulnerable to Cross Site Scripting (XSS)
Event Tickets with Ticket Scanner <= 1.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting