Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Tickera — Vulnerabilities & Security Advisories 15

Browse all 15 CVE security advisories affecting Tickera. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Tickera is a WordPress ticketing plugin for event management that has historically been vulnerable to multiple security issues, including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. The plugin has accumulated 10 CVEs to date, with several critical flaws allowing attackers to execute arbitrary code, steal sensitive data, or gain elevated access. Notable characteristics include improper input validation and insufficient access controls in its ticketing and registration functions. While no major public incidents have been widely documented, the consistent pattern of vulnerabilities across multiple versions highlights ongoing security challenges in its core functionality, particularly around user permissions and data handling.

CVE ID Title CVSS Severity Published
CVE-2026-82226 WordPress Tickera plugin <= 3.6.0.2 - PHP Object Injection vulnerability — Tickera CWE-502 9.8 Critical 2026-08-31
CVE-2026-15448 Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_order_status_filter' Parameter — Tickera – Sell Tickets & Manage Events CWE-89 6.5 Medium 2026-07-23
CVE-2026-15761 Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_event_filter' Parameter — Tickera – Sell Tickets & Manage Events CWE-89 6.5 Medium 2026-07-23
CVE-2026-13755 Tickera <= 3.6.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute — Tickera – Sell Tickets & Manage Events CWE-79 6.4 Medium 2026-07-16
CVE-2026-13754 Tickera <= 3.6.0.0 - Authenticated (Staff+) SQL Injection via 's' Parameter — Tickera – Sell Tickets & Manage Events CWE-89 6.5 Medium 2026-07-16
CVE-2025-12356 Tickera – WordPress Event Ticketing <= 3.5.6.4 - Missing Authorization to Authenticated (Subscriber+) Event/Post Status Update — Tickera – Sell Tickets & Manage Events CWE-862 4.3 Medium 2026-02-18
CVE-2025-67939 WordPress Tickera plugin <= 3.5.6.2 - Broken Access Control vulnerability — Tickera CWE-862 6.5 Medium 2026-01-22
CVE-2025-69355 WordPress Tickera plugin <= 3.5.6.4 - Broken Access Control vulnerability — Tickera CWE-862 4.3 Medium 2026-01-06
CVE-2025-58611 WordPress Tickera Plugin <= 3.5.5.6 - Cross Site Request Forgery (CSRF) Vulnerability — Tickera CWE-352 4.3 Medium 2025-09-03
CVE-2025-30851 WordPress Tickera plugin <= 3.5.5.2 - Broken Access Control vulnerability — Tickera CWE-862 4.3 Medium 2025-03-27
CVE-2024-12578 Tickera – WordPress Event Ticketing <= 3.5.4.8 - Unauthenticated Customer Data Exposure — Tickera – Sell Tickets & Manage Events CWE-200 5.3 Medium 2024-12-14
CVE-2024-11351 Restrict – membership, site, content and user access restrictions for WordPress <= 2.2.8 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Restrict – membership, site, content and user access restrictions for WordPress CWE-200 5.3 Medium 2024-12-11
CVE-2024-10263 Tickera – WordPress Event Ticketing <= 3.5.4.4 - Unauthenticated Arbitrary Shortcode Execution — Tickera – Sell Tickets & Manage Events CWE-94 7.3 High 2024-11-05
CVE-2024-5860 Tickera <= 3.5.2.8 - Missing Authorization to Authenticated (Susbcriber+) Ticket Deletion — Tickera – Sell Tickets & Manage Events CWE-862 4.3 Medium 2024-06-18
CVE-2024-35729 WordPress Tickera plugin <= 3.5.2.6 - Broken Access Control vulnerability — Tickera CWE-862 5.3 Medium 2024-06-10

This page lists every published CVE security advisory associated with Tickera. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.