CVE-2026-97634 Overview
CVE-2026-97634 is a SQL injection vulnerability in the Event Tickets and Registration plugin for WordPress, affecting all versions up to and including 5.29.5. The flaw resides in the handling of the orderby parameter, where user input is insufficiently escaped and the underlying SQL query is not properly prepared. Authenticated attackers with Contributor-level access or higher can append arbitrary SQL to existing queries and extract sensitive data from the WordPress database. The access gate (can_access_page()) only verifies post authorship rather than enforcing the edit_others_posts capability, which lowers the privilege barrier for exploitation.
Critical Impact
Authenticated Contributor-level users can exfiltrate sensitive database contents, including user credentials, session tokens, and private post data, through crafted orderby payloads.
Affected Products
- Event Tickets and Registration plugin for WordPress — all versions through 5.29.5
- WordPress sites running the vulnerable plugin with Contributor or higher user accounts enabled
- Fixed in the version released via WordPress Event Tickets Changeset 3711578
Discovery Timeline
- 2026-10-02 - CVE-2026-97634 published to the National Vulnerability Database (NVD)
- 2026-10-02 - Last updated in NVD database
Technical Details for CVE-2026-97634
Vulnerability Analysis
The vulnerability is a generic SQL injection [CWE-89] in the plugin's order and query repository code paths. User-controlled input flows into the orderby clause of SQL queries without being properly escaped or bound via prepared statements. Because the clause is concatenated into the final SQL string, an attacker can break out of the intended column reference and append subqueries that return arbitrary data from any table the database user can access.
The vulnerable code paths are located in the plugin's Commerce components, including src/Tickets/Commerce/Admin_Tables/Orders.php, src/Tickets/Commerce/Reports/Orders.php, and multiple sites within src/Tickets/Commerce/Repositories/Order_Repository.php. The shared filter logic in common/src/Tribe/Repository/Query_Filters.php passes the ordering input through to the query builder without sanitization.
Root Cause
The root cause is twofold. First, the orderby parameter is treated as a trusted column identifier and concatenated into SQL without allow-listing valid columns or escaping metacharacters. Second, the authorization gate can_access_page() permits any post author to reach the reporting endpoint for posts they own, instead of requiring the edit_others_posts capability. This combination elevates what should be an admin-only query surface into a Contributor-reachable one.
Attack Vector
An attacker authenticates with a Contributor-level WordPress account and creates or references a post they own. They then issue a request to the Orders reporting endpoint associated with that post, supplying a malicious orderby value. The injected SQL executes within the context of the WordPress database user, enabling data extraction through UNION-based or boolean-based techniques. No user interaction is required beyond the attacker's own authenticated session.
See the vendor-tracked source references for the affected lines, including WordPress Event Tickets Filter Code and the Wordfence Vulnerability Analysis DDF2625A for a technical walkthrough.
Detection Methods for CVE-2026-97634
Indicators of Compromise
- Web server access logs containing orderby= parameters with SQL keywords such as UNION, SELECT, SLEEP, BENCHMARK, or inline comment sequences (/*, --).
- Unusually long or URL-encoded orderby values submitted to Event Tickets Commerce reporting endpoints.
- Database error entries referencing ORDER BY syntax failures originating from the plugin's order repository code paths.
- Contributor-level user accounts generating authenticated requests to /wp-admin/ Commerce order reports they do not normally access.
Detection Strategies
- Deploy a web application firewall (WAF) rule set that inspects WordPress query parameters named orderby for SQL metacharacters and reject requests that do not match an allow-list of valid sort columns.
- Correlate authentication events for Contributor-level users with subsequent access to Event Tickets Commerce reporting URLs.
- Enable WordPress and MySQL query logging in staging environments to baseline normal orderby values used by the plugin.
Monitoring Recommendations
- Monitor outbound database query volume and row counts from the WordPress application user; sudden spikes may indicate data exfiltration.
- Alert on repeated HTTP 500 responses or SQL syntax errors returned from Event Tickets admin pages.
- Track creation of new Contributor-level accounts followed by access to admin reporting endpoints within short time windows.
How to Mitigate CVE-2026-97634
Immediate Actions Required
- Update the Event Tickets and Registration plugin to the patched release that supersedes 5.29.5 as published in WordPress Event Tickets Changeset 3711578.
- Audit WordPress user accounts and remove or downgrade unnecessary Contributor-level and higher accounts.
- Rotate database credentials, WordPress secret keys, and any API tokens stored in wp_options if exploitation is suspected.
- Review recent posts and user activity for accounts that may have been created solely to reach the vulnerable code path.
Patch Information
The vendor has published a corrected version via WordPress plugin changeset 3711578, which introduces proper escaping and column allow-listing for the orderby parameter and tightens the capability check in can_access_page(). Apply the update through the WordPress plugin manager or by deploying the patched release artifact to all affected sites.
Workarounds
- Temporarily deactivate the Event Tickets and Registration plugin until the patched version is deployed.
- Restrict access to /wp-admin/ Commerce reporting endpoints via server-side ACLs or WAF rules until patching is complete.
- Remove the Contributor role from any accounts that do not require content submission capabilities.
# Example WAF pattern to block SQL metacharacters in orderby for Event Tickets endpoints
# (Adapt to your WAF syntax; this is illustrative, not a drop-in rule)
SecRule ARGS:orderby "@rx (?i)(union|select|sleep|benchmark|--|/\*|;)" \
"id:1009763,phase:2,deny,status:403,msg:'Blocked SQLi attempt against Event Tickets orderby (CVE-2026-97634)'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.