Tickera – Sell Tickets & Manage Events <= 3.6.0.6 - Unauthenticated SQL Injection via Sales API 'period_compare' Parameter

High 7.5 CWE-89Fixed in 3.6.0.7
ID
WPSEC-2026-0523
Plugin
Tickera – Sell Tickets & Manage Events (tickera-event-ticketing-system)
Affected
all versions before 3.6.0.7
Remediation
Update to 3.6.0.7 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness
CWE-89
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Tickera – Sell Tickets & Manage Events on WPSec AttackSurface
Fix released
Published

Description

The Tickera plugin for WordPress is vulnerable to SQL Injection via the 'period_compare' parameter of the Sales API in all versions up to, and including, 3.6.0.6. This is due to the parameter being concatenated directly into the SQL WHERE clause of the order search with only text sanitization, without an operator allowlist or prepared statement. Because the Sales API in these versions also accepts an empty API key, this makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0