Extension WordPress

Vulnérabilités Tickera – Sell Tickets & Manage Events

Cette page rassemble les failles publiées pour Tickera – Sell Tickets & Manage Events, leurs plages de versions affectées et les correctifs signalés dans la base locale.

16Vulnérabilités
0Critiques
16Avec correctif
7,3CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Tickera – Sell Tickets & Manage Events

16 fiches

CVE-2026-13755 Moyenne · 6,4
Tickera – Sell Tickets & Manage Events

Tickera <= 3.6.0.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute in all versions up to, and including, 3.6.0.0 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-3.6.0.0

Correctif

3.6.0.1

Publication

15/07/2026

CVE-2025-12356 Moyenne · 4,3
Tickera – Sell Tickets & Manage Events

Tickera – WordPress Event Ticketing <= 3.5.6.4 – Missing Authorization to Authenticated (Subscriber+) Event/Post Status Update

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_change_ticket_status' AJAX endpoint in all versions up to, and including, 3.5.6.4. This…

Versions affectées

*-3.5.6.4

Correctif

3.5.6.5

Publication

17/02/2026

CVE-2024-12578 Moyenne · 5,3
Tickera – Sell Tickets & Manage Events

Tickera – WordPress Event Ticketing <= 3.5.4.8 – Unauthenticated Customer Data Exposure

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.5.4.8 via the 'tickera_tickets_info' endpoint. This makes it possible for unauthenticated attackers to extract sensitive data from…

Versions affectées

*-3.5.4.8

Correctif

3.5.4.9

Publication

13/12/2024

CVE-2024-10263 Élevée · 7,3
Tickera – Sell Tickets & Manage Events

Tickera – WordPress Event Ticketing <= 3.5.4.4 – Unauthenticated Arbitrary Shortcode Execution

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.4. This is due to the software allowing users to execute an action that does not…

Versions affectées

*-3.5.4.4

Correctif

3.5.4.6

Publication

04/11/2024

CVE-2024-5860 Moyenne · 4,3
Tickera – Sell Tickets & Manage Events

Tickera <= 3.5.2.8 – Missing Authorization to Authenticated (Susbcriber+) Ticket Deletion

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tc_dl_delete_tickets AJAX action in all versions up to, and including, 3.5.2.8. This makes it…

Versions affectées

*-3.5.2.8

Correctif

3.5.2.9

Publication

17/06/2024

CVE-2023-7252 Moyenne · 5,3
Tickera – Sell Tickets & Manage Events

Tickera – WordPress Event Ticketing <= 3.5.2.4 – Insecure Direct Object Reference to Information Exposure

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.5.2.4 via the order_key parameter due to missing validation on the user controlled key. This…

Versions affectées

*-3.5.2.4

Correctif

3.5.2.5

Publication

01/04/2024

CVE-2023-23726 Moyenne · 4,3
Tickera – Sell Tickets & Manage Events

Tickera <= 3.5.1.0 – Cross-Site Request Forgery to Ticket Post Status Change

The Tickera plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.1.0. This is due to missing nonce validation in the tc_get_ticket_type_instances function. This makes it possible for unauthenticated attackers to change…

Versions affectées

*-3.5.1.0

Correctif

3.5.1.1

Publication

14/02/2023

CVE-2022-4549 Moyenne · 4,3
Tickera – Sell Tickets & Manage Events

Tickera <= 3.4.9.9 – Cross-Site Request Forgery to Plugin Data Deletion & Settings Changes

The Tickera plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.9.9. This is due to missing nonce validation in the ~/includes/addons/delete-info/includes/admin-pages/settings-tickera_delete_info.php file. This makes it possible for unauthenticated attackers to delete…

Versions affectées

*-3.4.9.9

Correctif

3.5.1.0

Publication

23/12/2022

CVE-2022-4974 Moyenne · 6,3
Tickera – Sell Tickets & Manage Events

Freemius SDK <= 2.4.2 – Missing Authorization Checks

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…

Versions affectées

[*, 3.4.9.2)

Correctif

3.4.9.2

Publication

04/03/2022

CVE-2021-24797 Élevée · 7,2
Tickera – Sell Tickets & Manage Events

Tickera <= 3.4.8.2 – Unauthenticated Stored Cross-Site Scripting

The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events before outputting them in the Orders admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.

Versions affectées

*-3.4.8.2

Correctif

3.4.8.3

Publication

23/11/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités