CVE-2026-41471 Details
Description
The Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains an information disclosure vulnerability in the QR code scanning endpoint that allows unauthenticated attackers to enumerate and retrieve all customer order records. Attackers can iterate over sequential WordPress post IDs through the scan_qr.php endpoint to harvest the complete set of orders stored in the database without requiring authentication or prior knowledge of specific order identifiers.
A vulnerability allowing information disclosure has been identified in the Easy PayPal Events & Tickets WordPress plugin, specifically in versions through 1.3. This vulnerability resides in the QR code scanning endpoint, where unauthenticated attackers can enumerate and access all customer order records. The exploitation involves iterating over sequential WordPress post IDs via the scan_qr.php endpoint, enabling attackers to collect a comprehensive set of orders from the database without authentication or prior knowledge of specific order identifiers.
Users are advised to implement authorization checks, use non-predictable identifiers, and restrict access to authenticated users.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 4, 2026CISA-ADP
Assessed May 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Easy PayPal Events & Tickets | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Modified | [email protected] |
| May 4, 2026 | New CVE Received | [email protected] |
Volerion