Extension WordPress
Vulnérabilités Tickera – Sell Tickets & Manage Events
Cette page rassemble les failles publiées pour Tickera – Sell Tickets & Manage Events, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Tickera – Sell Tickets & Manage Events
16 fiches
Tickera <= 3.6.0.0 – Authenticated (Staff+) SQL Injection via 's' Parameter
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 3.6.0.0 due to insufficient escaping on the user supplied parameter…
*-3.6.0.0
3.6.0.1
15/07/2026
Tickera <= 3.6.0.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute in all versions up to, and including, 3.6.0.0 due to insufficient input sanitization and output escaping. This…
*-3.6.0.0
3.6.0.1
15/07/2026
Tickera – WordPress Event Ticketing <= 3.5.6.4 – Missing Authorization to Authenticated (Subscriber+) Event/Post Status Update
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_change_ticket_status' AJAX endpoint in all versions up to, and including, 3.5.6.4. This…
*-3.5.6.4
3.5.6.5
17/02/2026
Tickera <= 3.5.6.2 – Missing Authorization
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.6.2. This makes it possible for…
*-3.5.6.2
3.5.6.3
16/01/2026
Tickera <= 3.5.6.4 – Missing Authorization
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.6.4. This makes it possible for…
*-3.5.6.4
3.5.6.5
09/01/2026
Tickera <= 3.5.5.6 – Cross-Site Request Forgery
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.5.6. This is due to missing or incorrect nonce validation on a function. This makes it…
*-3.5.5.6
3.5.5.8
03/09/2025
Tickera <= 3.5.5.2 – Missing Authorization
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.5.2. This makes it possible for authenticated attackers,…
*-3.5.5.2
3.5.5.3
27/03/2025
Tickera – WordPress Event Ticketing <= 3.5.4.8 – Unauthenticated Customer Data Exposure
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.5.4.8 via the 'tickera_tickets_info' endpoint. This makes it possible for unauthenticated attackers to extract sensitive data from…
*-3.5.4.8
3.5.4.9
13/12/2024
Tickera – WordPress Event Ticketing <= 3.5.4.4 – Unauthenticated Arbitrary Shortcode Execution
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.4. This is due to the software allowing users to execute an action that does not…
*-3.5.4.4
3.5.4.6
04/11/2024
Tickera <= 3.5.2.8 – Missing Authorization to Authenticated (Susbcriber+) Ticket Deletion
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tc_dl_delete_tickets AJAX action in all versions up to, and including, 3.5.2.8. This makes it…
*-3.5.2.8
3.5.2.9
17/06/2024
Tickera <= 3.5.2.6 – Missing Authorization
The Tickera plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the generate_ticket_preview() function in versions up to, and including, 3.5.2.6. This makes it possible for authenticated attackers, with contributor-level…
*-3.5.2.6
3.5.2.7
06/06/2024
Tickera – WordPress Event Ticketing <= 3.5.2.4 – Insecure Direct Object Reference to Information Exposure
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.5.2.4 via the order_key parameter due to missing validation on the user controlled key. This…
*-3.5.2.4
3.5.2.5
01/04/2024
Tickera <= 3.5.1.0 – Cross-Site Request Forgery to Ticket Post Status Change
The Tickera plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.1.0. This is due to missing nonce validation in the tc_get_ticket_type_instances function. This makes it possible for unauthenticated attackers to change…
*-3.5.1.0
3.5.1.1
14/02/2023
Tickera <= 3.4.9.9 – Cross-Site Request Forgery to Plugin Data Deletion & Settings Changes
The Tickera plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.9.9. This is due to missing nonce validation in the ~/includes/addons/delete-info/includes/admin-pages/settings-tickera_delete_info.php file. This makes it possible for unauthenticated attackers to delete…
*-3.4.9.9
3.5.1.0
23/12/2022
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 3.4.9.2)
3.4.9.2
04/03/2022
Tickera <= 3.4.8.2 – Unauthenticated Stored Cross-Site Scripting
The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events before outputting them in the Orders admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.
*-3.4.8.2
3.4.8.3
23/11/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.