Junglewise Threat Intelligence

CVE-2026-13754: Tickera Sell Tickets & Manage Events SQL injection in s parameter

CVE-2026-13754 · Severity: medium · CVSS 6.5 · Published 2026-07-16

Executive brief

The Tickera plugin for WordPress, which is used to manage event ticket sales, contains a security flaw that allows certain logged-in users to access sensitive information from the website's database. By sending specially crafted search requests, an attacker could bypass security measures to view data they are not authorized to see. This could lead to the exposure of customer details or internal site configuration.

Technical details

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to a generic SQL Injection vulnerability due to insufficient escaping of the 's' parameter and a lack of SQL query preparation in the 'better-attendees-and-tickets' add-on. This flaw exists in all versions up to and including 3.6.0.0. An authenticated attacker with custom-level access or higher can exploit this by appending malicious SQL commands to existing queries. Successful exploitation allows the attacker to extract sensitive information from the WordPress database. A patch appears to be available in the plugin's changeset repository.

Affected products

  • Tickera Tickera – Sell Tickets & Manage Events up to, and including, 3.6.0.0

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory

References

Related threats