# Tickera – Sell Tickets & Manage Events <= 3.6.0.6 - Unauthenticated SQL Injection via Sales API 'period_compare' Parameter

- **ID:** WPSEC-2026-0523
- **Plugin:** Tickera – Sell Tickets & Manage Events (`tickera-event-ticketing-system`), https://wordpress.org/plugins/tickera-event-ticketing-system/
- **Affected versions:** all versions before 3.6.0.7
- **Fixed in:** 3.6.0.7 (Update to 3.6.0.7 or later.)
- **Severity:** High 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **Weakness:** CWE-89
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/tickera-event-ticketing-system
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0523/

## Description

The Tickera plugin for WordPress is vulnerable to SQL Injection via the 'period_compare' parameter of the Sales API in all versions up to, and including, 3.6.0.6. This is due to the parameter being concatenated directly into the SQL WHERE clause of the order search with only text sanitization, without an operator allowlist or prepared statement. Because the Sales API in these versions also accepts an empty API key, this makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

## References

- https://wpsec.com/vuln/WPSEC-2026-0523/
- https://plugins.svn.wordpress.org/tickera-event-ticketing-system/tags/3.6.0.7/
- https://wordpress.org/plugins/tickera-event-ticketing-system/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0523/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
