Tickera – Sell Tickets & Manage Events <= 3.6.0.6 - Unauthenticated Sales API Authentication Bypass via Empty API Key

Medium 5.3 CWE-287Fixed in 3.6.0.7
ID
WPSEC-2026-0524
Plugin
Tickera – Sell Tickets & Manage Events (tickera-event-ticketing-system)
Affected
all versions before 3.6.0.7
Remediation
Update to 3.6.0.7 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-287
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Tickera – Sell Tickets & Manage Events on WPSec AttackSurface
Fix released
Published

Description

The Tickera plugin for WordPress is vulnerable to Authentication Bypass in the Sales API in all versions up to, and including, 3.6.0.6. This is due to the API key lookup passing an empty api_key value to a meta query that then matches any existing API key instead of none. This makes it possible for unauthenticated attackers to pass the Sales API credential check and query its sales statistics endpoint (revenue, currency and order count), and it exposes the Sales API's 'period_compare' SQL Injection to unauthenticated attackers. The plugin creates a default API key during setup, so most installations are affected.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0