Tickera – Sell Tickets & Manage Events <= 3.6.0.6 - Unauthenticated SQL Injection via Sales API 'period_compare' Parameter
- ID
- WPSEC-2026-0523
- Plugin
- Tickera – Sell Tickets & Manage Events (tickera-event-ticketing-system)
- Affected
- all versions before 3.6.0.7
- Remediation
- Update to 3.6.0.7 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Weakness
- CWE-89
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- Tickera – Sell Tickets & Manage Events on WPSec AttackSurface
- Fix released
- Published
Description
The Tickera plugin for WordPress is vulnerable to SQL Injection via the 'period_compare' parameter of the Sales API in all versions up to, and including, 3.6.0.6. This is due to the parameter being concatenated directly into the SQL WHERE clause of the order search with only text sanitization, without an operator allowlist or prepared statement. Because the Sales API in these versions also accepts an empty API key, this makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
References
- https://wpsec.com/vuln/WPSEC-2026-0523/
- https://plugins.svn.wordpress.org/tickera-event-ticketing-system/tags/3.6.0.7/
- https://wordpress.org/plugins/tickera-event-ticketing-system/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS