Tickera – Sell Tickets & Manage Events <= 3.6.0.6 - Unauthenticated Sales API Authentication Bypass via Empty API Key
- ID
- WPSEC-2026-0524
- Plugin
- Tickera – Sell Tickets & Manage Events (tickera-event-ticketing-system)
- Affected
- all versions before 3.6.0.7
- Remediation
- Update to 3.6.0.7 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-287
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- Tickera – Sell Tickets & Manage Events on WPSec AttackSurface
- Fix released
- Published
Description
The Tickera plugin for WordPress is vulnerable to Authentication Bypass in the Sales API in all versions up to, and including, 3.6.0.6. This is due to the API key lookup passing an empty api_key value to a meta query that then matches any existing API key instead of none. This makes it possible for unauthenticated attackers to pass the Sales API credential check and query its sales statistics endpoint (revenue, currency and order count), and it exposes the Sales API's 'period_compare' SQL Injection to unauthenticated attackers. The plugin creates a default API key during setup, so most installations are affected.
References
- https://wpsec.com/vuln/WPSEC-2026-0524/
- https://plugins.svn.wordpress.org/tickera-event-ticketing-system/tags/3.6.0.7/
- https://wordpress.org/plugins/tickera-event-ticketing-system/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS