{
 "id": "WPSEC-2026-0524",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0524/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0524/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0524/index.md",
 "title": "Tickera – Sell Tickets & Manage Events <= 3.6.0.6 - Unauthenticated Sales API Authentication Bypass via Empty API Key",
 "description": "The Tickera plugin for WordPress is vulnerable to Authentication Bypass in the Sales API in all versions up to, and including, 3.6.0.6. This is due to the API key lookup passing an empty api_key value to a meta query that then matches any existing API key instead of none. This makes it possible for unauthenticated attackers to pass the Sales API credential check and query its sales statistics endpoint (revenue, currency and order count), and it exposes the Sales API's 'period_compare' SQL Injection to unauthenticated attackers. The plugin creates a default API key during setup, so most installations are affected.",
 "plugin": {
  "slug": "tickera-event-ticketing-system",
  "name": "Tickera – Sell Tickets & Manage Events",
  "full_name": "Tickera – Sell Tickets & Manage Events",
  "wordpress_org": "https://wordpress.org/plugins/tickera-event-ticketing-system/",
  "advisories_url": "https://wpsec.com/vuln/plugin/tickera-event-ticketing-system/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/tickera-event-ticketing-system"
 },
 "type": "AUTH",
 "cwe": [
  "CWE-287"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "3.6.0.7",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 3.6.0.7"
  ]
 },
 "introduced_in": null,
 "fixed_in": "3.6.0.7",
 "remediation": "Update to 3.6.0.7 or later.",
 "fix_released": "2026-10-06T12:17:22+00:00",
 "published": "2026-10-07T12:46:23+00:00",
 "updated": "2026-10-07T11:59:32.979240+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0524/",
  "https://plugins.svn.wordpress.org/tickera-event-ticketing-system/tags/3.6.0.7/",
  "https://wordpress.org/plugins/tickera-event-ticketing-system/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/tickera-event-ticketing-system",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}