Liquidweb offers a suite of WordPress plugins and content-management tools, including Event Tickets, Restrict Content, and WPComplete, that serve web publishers and site administrators with ticketing, access control, and course functionality. The recurring vulnerability patterns center on authorization and access-control weaknesses—including improper authentication checks, user-controlled access keys, and sensitive-information exposure—that are characteristic of plugins managing restricted content and user boundaries. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Liquidweb over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14844HIGH The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 via the 'rcp_stripe_create_setup_ | Jan 16, 2026 | 8.2 | 30 | NO | NO |
CVE-2019-16120HIGH CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature. | Sep 8, 2019 | 8.8 | 29 | NO | NO |
CVE-2024-1316MEDIUM The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from l | Mar 4, 2024 | 6.5 | 23 | NO | NO |
CVE-2024-11090HIGH The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.13 via the WordPress core se | Jan 26, 2025 | 7.5 | 22 | NO | NO |
CVE-2023-47668HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StellarWP Membership Plugin – Restrict Content plugin <= 3.2.7 versions. | Nov 23, 2023 | 7.5 | 21 | NO | NO |
CVE-2022-45825MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in iThemes WPComplete plugin <= 2.9.2 versions. | Mar 28, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-3182MEDIUM The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could | Jul 17, 2023 | 6.1 | 19 | NO | NO |
CVE-2024-13457MEDIUM The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter | Jan 30, 2025 | 5.3 | 17 | NO | NO |
CVE-2024-1053MEDIUM The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, | Feb 22, 2024 | 4.3 | 16 | NO | NO |
CVE-2024-1319MEDIUM The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of statu | Mar 4, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Liquidweb.
Media articles that mention a CVE ID that affects a product developed by Liquidweb — matched by CVE ID, not by vendor name.