Security Issue: A registered user tried to purchase a pending event ticket

Home Forums Ticket Products Community Tickets Security Issue: A registered user tried to purchase a pending event ticket

Viewing 5 posts - 1 through 5 (of 5 total)
  • Author
    Posts
  • #1160732
    Tac
    Participant

    Hi,

    Recently, we had a potential security threat. A registered user(email) on our website tried to purchase an event ticket which was still in pending stage.

    We are using Community Events, Community Tickets plugins as well. Payment gateway used on our website is Stripe.
    Scenario:
    1. A user is registered on our website(May be a fake user)
    2. An event is submitted on our website by another registered user(potentially a fake event)
    3. User from Step 1 tried to purchase tickets. The user could add ticket to cart and processed payment. Stripe, however, rejected the payment for some reason and purchase was not successful

    Questions:
    1. Can you please advise how the user could get through to an event owned by another user and that event is still in pending stage(Not yet approved)?
    2. What we can do to increase security?

    Thanks.

    #1161241
    Cliff
    Member

    Hi.

    Thanks for your detailed question.

    Could you please specify what you have wp-admin > Events > Settings > Community > “Default status for submitted events” option

    I’m guessing you have them set to Pending Review and that this wouldn’t happen if you set them to Draft instead.

    Please let me know.

    #1161245
    Tac
    Participant

    Hi Cliff,

    You are right! The default setting we use is Pending Review.

    I’ve changed it to “Draft” now! I hope it helps going forward.

    Thank you.

    #1161274
    Cliff
    Member

    Could you please go through your testing to see if the scenario you previously described is still possible while setting to Draft instead of to Pending Review?

    #1170512
    Support Droid
    Keymaster

    Hey there! This thread has been pretty quiet for the last three weeks, so we’re going to go ahead and close it to avoid confusion with other topics. If you’re still looking for help with this, please do open a new thread, reference this one and we’d be more than happy to continue the conversation over there.

    Thanks so much!
    The Events Calendar Support Team

Viewing 5 posts - 1 through 5 (of 5 total)
  • The topic ‘Security Issue: A registered user tried to purchase a pending event ticket’ is closed to new replies.