plugin

Tickera Event Ticketing System Vulnerabilities

38 known security issues reported for the Tickera Event Ticketing System WordPress plugin. Most recent disclosed Jul 22, 2026.

2 high 16 medium

Running Tickera Event Ticketing System on your site? Check whether your installed version is affected.

Scan your site free

Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_order_status_filter' Parameter

medium

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This m...

CVSS:
6.5
Affected:
up to 3.6.0.1
Fixed in:
3.6.0.2
Disclosed:
Jul 22, 2026

CVE-2026-15448 on NVD →

Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_event_filter' Parameter

medium

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it...

CVSS:
6.5
Affected:
up to 3.6.0.1
Fixed in:
3.6.0.2
Disclosed:
Jul 22, 2026

CVE-2026-15761 on NVD →

Tickera <= 3.6.0.0 - Authenticated (Staff+) SQL Injection via 's' Parameter

medium

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 3.6.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for...

CVSS:
6.5
Affected:
up to 3.6.0.0
Fixed in:
3.6.0.1
Disclosed:
Jul 15, 2026

CVE-2026-13754 on NVD →

Tickera <= 3.6.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute

medium

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute in all versions up to, and including, 3.6.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contribu...

CVSS:
6.4
Affected:
up to 3.6.0.0
Fixed in:
3.6.0.1
Disclosed:
Jul 15, 2026

CVE-2026-13755 on NVD →

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.5.6.5

unknown

[en] The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_change_ticket_status' AJAX endpoint in all versions up to, and including, 3.5.6.4. This makes it possible for authenticated attackers, with Subscriber...

Affected:
up to 3.5.6.5
Fixed in:
3.5.6.5
Disclosed:
Feb 18, 2026

CVE-2025-12356 on NVD →

Tickera – WordPress Event Ticketing <= 3.5.6.4 - Missing Authorization to Authenticated (Subscriber+) Event/Post Status Update

medium

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_change_ticket_status' AJAX endpoint in all versions up to, and including, 3.5.6.4. This makes it possible for authenticated attackers, with Subscriber-leve...

CVSS:
4.3
Affected:
up to 3.5.6.4
Fixed in:
3.5.6.5
Disclosed:
Feb 17, 2026

CVE-2025-12356 on NVD →

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] <= 3.5.6.2 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tickera: from n/a through <= 3.5.6.2.

Affected:
up to 3.5.6.2
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-67939 on NVD →

Tickera <= 3.5.6.2 - Missing Authorization

medium

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.6.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized actio...

CVSS:
4.3
Affected:
up to 3.5.6.2
Fixed in:
3.5.6.3
Disclosed:
Jan 16, 2026

CVE-2025-67939 on NVD →

Tickera <= 3.5.6.4 - Missing Authorization

medium

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.6.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized actio...

CVSS:
4.3
Affected:
up to 3.5.6.4
Fixed in:
3.5.6.5
Disclosed:
Jan 9, 2026

CVE-2025-69355 on NVD →

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] <= 3.5.6.4 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tickera: from n/a through <= 3.5.6.4.

Affected:
up to 3.5.6.4
Fix:
No patched version reported
Disclosed:
Jan 6, 2026

CVE-2025-69355 on NVD →

Tickera <= 3.5.5.6 - Cross-Site Request Forgery

medium

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.5.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they...

CVSS:
4.3
Affected:
up to 3.5.5.6
Fixed in:
3.5.5.8
Disclosed:
Sep 3, 2025

CVE-2025-58611 on NVD →

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.5.5.8 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Tickera Tickera allows Cross Site Request Forgery. This issue affects Tickera: from n/a through 3.5.5.6.

Affected:
up to 3.5.5.8
Fixed in:
3.5.5.8
Disclosed:
Sep 3, 2025

CVE-2025-58611 on NVD →

Tickera <= 3.5.5.2 - Missing Authorization

medium

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.5.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.5.5.2
Fixed in:
3.5.5.3
Disclosed:
Mar 27, 2025

CVE-2025-30851 on NVD →

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.5.5.3 (closed)

unknown

[en] Missing Authorization vulnerability in Tickera Tickera allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Tickera: from n/a through 3.5.5.2.

Affected:
up to 3.5.5.3
Fixed in:
3.5.5.3
Disclosed:
Mar 27, 2025

CVE-2025-30851 on NVD →

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.5.4.9 (closed)

unknown

[en] The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.5.4.8 via the 'tickera_tickets_info' endpoint. This makes it possible for unauthenticated attackers to extract sensitive data from bookings like full names, email addresses, ch...

Affected:
up to 3.5.4.9
Fixed in:
3.5.4.9
Disclosed:
Dec 14, 2024

CVE-2024-12578 on NVD →

Tickera – WordPress Event Ticketing <= 3.5.4.8 - Unauthenticated Customer Data Exposure

medium

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.5.4.8 via the 'tickera_tickets_info' endpoint. This makes it possible for unauthenticated attackers to extract sensitive data from bookings like full names, email addresses, check-i...

CVSS:
5.3
Affected:
up to 3.5.4.8
Fixed in:
3.5.4.9
Disclosed:
Dec 13, 2024

CVE-2024-12578 on NVD →

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.5.1.1 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Tickera.com Tickera allows Cross Site Request Forgery.This issue affects Tickera: from n/a through 3.5.1.0.

Affected:
up to 3.5.1.1
Fixed in:
3.5.1.1
Disclosed:
Dec 9, 2024

CVE-2023-23726 on NVD →

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.5.4.6 (closed)

unknown

[en] The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for...

Affected:
up to 3.5.4.6
Fixed in:
3.5.4.6
Disclosed:
Nov 5, 2024

CVE-2024-10263 on NVD →

Tickera – WordPress Event Ticketing <= 3.5.4.4 - Unauthenticated Arbitrary Shortcode Execution

high

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unaut...

CVSS:
7.3
Affected:
up to 3.5.4.4
Fixed in:
3.5.4.6
Disclosed:
Nov 4, 2024

CVE-2024-10263 on NVD →

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.4.9.2 (closed)

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 3.4.9.2
Fixed in:
3.4.9.2
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.5.2.9 (closed)

unknown

[en] The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tc_dl_delete_tickets AJAX action in all versions up to, and including, 3.5.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above...

Affected:
up to 3.5.2.9
Fixed in:
3.5.2.9
Disclosed:
Jun 18, 2024

CVE-2024-5860 on NVD →

Tickera <= 3.5.2.8 - Missing Authorization to Authenticated (Susbcriber+) Ticket Deletion

medium

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tc_dl_delete_tickets AJAX action in all versions up to, and including, 3.5.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...

CVSS:
4.3
Affected:
up to 3.5.2.8
Fixed in:
3.5.2.9
Disclosed:
Jun 17, 2024

CVE-2024-5860 on NVD →

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.5.2.7 (closed)

unknown

[en] Missing Authorization vulnerability in Tickera.This issue affects Tickera: from n/a through 3.5.2.6.

Affected:
up to 3.5.2.7
Fixed in:
3.5.2.7
Disclosed:
Jun 10, 2024

CVE-2024-35729 on NVD →

Tickera <= 3.5.2.6 - Missing Authorization

medium

The Tickera plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the generate_ticket_preview() function in versions up to, and including, 3.5.2.6. This makes it possible for authenticated attackers, with contributor-level access and above, to generate ticket previews.

CVSS:
4.3
Affected:
up to 3.5.2.6
Fixed in:
3.5.2.7
Disclosed:
Jun 6, 2024

CVE-2024-35729 on NVD →

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.5.2.5 (closed)

unknown

[en] The Tickera WordPress plugin before 3.5.2.5 does not prevent users from leaking other users' tickets.

Affected:
up to 3.5.2.5
Fixed in:
3.5.2.5
Disclosed:
Apr 22, 2024

CVE-2023-7252 on NVD →

Tickera – WordPress Event Ticketing <= 3.5.2.4 - Insecure Direct Object Reference to Information Exposure

medium

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.5.2.4 via the order_key parameter due to missing validation on the user controlled key. This makes it possible for unauthenticated attackers to view other users tickets

CVSS:
5.3
Affected:
up to 3.5.2.4
Fixed in:
3.5.2.5
Disclosed:
Apr 1, 2024

CVE-2023-7252 on NVD →

Tickera <= 3.5.1.0 - Cross-Site Request Forgery to Ticket Post Status Change

medium

The Tickera plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.1.0. This is due to missing nonce validation in the tc_get_ticket_type_instances function. This makes it possible for unauthenticated attackers to change a ticket post status via a forged request granted t...

CVSS:
4.3
Affected:
up to 3.5.1.0
Fixed in:
3.5.1.1
Disclosed:
Feb 14, 2023

CVE-2023-23726 on NVD →

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.5.1.0 (closed)

unknown

[en] The Tickera WordPress plugin before 3.5.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

Affected:
up to 3.5.1.0
Fixed in:
3.5.1.0
Disclosed:
Jan 16, 2023

CVE-2022-4549 on NVD →

Tickera <= 3.4.9.9 - Cross-Site Request Forgery to Plugin Data Deletion & Settings Changes

medium

The Tickera plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.9.9. This is due to missing nonce validation in the ~/includes/addons/delete-info/includes/admin-pages/settings-tickera_delete_info.php file. This makes it possible for unauthenticated attackers to delete...

CVSS:
4.3
Affected:
up to 3.4.9.9
Fixed in:
3.5.1.0
Disclosed:
Dec 23, 2022

CVE-2022-4549 on NVD →

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 3.4.9.2
Fixed in:
3.4.9.2
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.4.9.2 (closed)

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 3.4.9.2
Fixed in:
3.4.9.2
Disclosed:
Mar 4, 2022

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.4.9.2 (closed)

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress Tickera plugin (versions < 3.4.9.2).

Affected:
up to 3.4.9.2
Fixed in:
3.4.9.2
Disclosed:
Feb 28, 2022

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.4.9.2 (closed)

unknown

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Tickera plugin (versions < 3.4.9.2).

Affected:
up to 3.4.9.2
Fixed in:
3.4.9.2
Disclosed:
Feb 28, 2022

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.4.9.2 (closed)

unknown

[en] The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events before outputting them in the Orders admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.

Affected:
up to 3.4.9.2
Fixed in:
3.4.9.2
Disclosed:
Dec 27, 2021

CVE-2021-24797 on NVD →

Tickera <= 3.4.8.2 - Unauthenticated Stored Cross-Site Scripting

high

The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events before outputting them in the Orders admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.

CVSS:
7.2
Affected:
up to 3.4.8.2
Fixed in:
3.4.8.3
Disclosed:
Nov 23, 2021

CVE-2021-24797 on NVD →

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.4.6.9 (closed)

unknown

Sensitive Data Exposure vulnerability discovered by Florian Hauser in WordPress Tickera plugin (versions <= 3.4.6.7).

Affected:
up to 3.4.6.9
Fixed in:
3.4.6.9
Disclosed:
Apr 11, 2020

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.4.6.9 (closed)

unknown

Due to missing authorization controls in the &quot;admin_init&quot; hooks, all personal data from registered users of an event could be exported into a downloadable PDF file by every unauthenticated user. The event ID could be read from the page source and/or easily enumerated in sequence. According to the original...

Affected:
up to 3.4.6.9
Fixed in:
3.4.6.9

Tickera – Sell Tickets &amp; Manage Events [tickera-event-ticketing-system] < 3.4.8.4 (closed)

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 3.4.8.4
Fixed in:
3.4.8.4

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database