Project

General

Profile

Bug #15254

Event Tickets plugin can create new user accounts and bypass BuddyPress registration

Added by Raymond Hoh 5 months ago. Updated 5 months ago.

Status:
Resolved
Priority name:
Normal
Assignee:
Category name:
WordPress Plugins
Target version:
Start date:
2022-02-03
Due date:
% Done:

0%

Estimated time:

Description

Just encountered an issue on the NYCDH site where the Event Tickets plugin was activated on the sub-site and it was able to bypass the main BuddyPress registration page.

The Events Tickets plugin has a RSVP module that will allow a user to RSVP for an event through a web form. This web form doesn't require a user to be authenticated and will create a new user in WordPress by default. It is possible to to allow only logged-in users to RSVP for an event, but this option must be enabled under "Events > Settings > Tickets" in the admin dashboard.

Will look to only allow logged-in users to RSVP for events with a code snippet.


Related issues

Related to NYCDH Community Site - Bug #15247: Registration issueResolved2022-02-02

History

#1 Updated by Raymond Hoh 5 months ago

#2 Updated by Raymond Hoh 5 months ago

  • Status changed from New to Staged for Production Release

Fixed in https://github.com/cuny-academic-commons/cac/commit/9784eebaba1bf3f35d2234165a9c0658355f7742.

I'm using the 'tribe_tickets_attendee_create_user_from_email' filter to disable WordPress user creation instead since a site might want to allow anonymous users to RSVP for an event.

#3 Updated by Boone Gorges 5 months ago

  • Status changed from Staged for Production Release to Resolved

Also available in: Atom PDF