CVE-2026-32834Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains a hardcoded authentication bypass vulnerability in the QR code scanning functionality that allows unauthenticated remote attackers to bypass hash verification by supplying 'test' as the hash parameter. Attackers can access the vulnerable endpoint via the add_wpeevent_button_qr action to retrieve sensitive order details including PayPal transaction IDs, customer email addresses, purchase amounts, and ticket information for any order with a known or guessed post ID.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-04: 2Technical Details · 2026-05-04: 205-04
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32834 Authentication Bypass in Easy PayPal Events & Tickets Plugin for WordPress 1.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32834

    Post summary

    The entry announces an authentication bypass vulnerability (CVE-2026-32834) affecting Easy PayPal Events & Tickets Plugin for WordPress 1.3, without providing exploit details, active use evidence, or patch information.

    0000039
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32834 Easy PayPal Events & Tickets plugin for WordPress version 1.3 and earlier contain a hardcoded authentication bypass vulnerability in the QR code scanning functionalit… https://www.cve.org/CVERecord?id=CVE-2026-32834

    Post summary

    CVE-2026-32834 reveals a hardcoded authentication bypass in the Easy PayPal Events & Tickets WordPress plugin (v1.3 and earlier). No PoC, exploitation, or patch details are reported.

    00000107
    57.4K followersView on X

Explore more