Executive brief
The Tickera plugin for WordPress, which is used to manage event ticket sales, contains a security flaw that allows authorized staff members to run unauthorized database commands. By exploiting this vulnerability, a user with staff-level access could bypass security controls to view sensitive information stored in the website's database. This could lead to the exposure of customer data or internal event details.
Technical details
The Tickera plugin for WordPress is vulnerable to a generic SQL injection vulnerability due to insufficient escaping of the 'tc_order_status_filter' parameter and a lack of proper SQL query preparation. This flaw exists within the 'Better Attendees and Tickets' add-on component. An authenticated attacker with staff-level privileges or higher can inject malicious SQL commands into existing queries. This allows for the extraction of sensitive data from the WordPress database. The vulnerability is addressed in versions following 3.6.0.1.
Affected products
- Tickera Tickera – Sell Tickets & Manage Events up to, and including, 3.6.0.1
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory
References
- https://plugins.trac.wordpress.org/browser/tickera-event-ticketing-system/tags/3.6.0.0/includes/addons/better-attendees-and-tickets/index.php
- https://plugins.trac.wordpress.org/browser/tickera-event-ticketing-system/tags/3.6.0.0/includes/addons/better-attendees-and-tickets/index.php
- https://plugins.trac.wordpress.org/browser/tickera-event-ticketing-system/tags/3.6.0.0/includes/addons/better-attendees-and-tickets/index.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3618136%40tickera-event-ticketing-system&new=3618136%40tickera-event-ticketing-system
- https://www.wordfence.com/threat-intel/vulnerabilities/id/8972b507-4aae-40cc-a79e-2603dbdc70c0?source=cve