# Tickera – Sell Tickets & Manage Events <= 3.6.0.6 - Unauthenticated Sales API Authentication Bypass via Empty API Key

- **ID:** WPSEC-2026-0524
- **Plugin:** Tickera – Sell Tickets & Manage Events (`tickera-event-ticketing-system`), https://wordpress.org/plugins/tickera-event-ticketing-system/
- **Affected versions:** all versions before 3.6.0.7
- **Fixed in:** 3.6.0.7 (Update to 3.6.0.7 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-287
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/tickera-event-ticketing-system
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0524/

## Description

The Tickera plugin for WordPress is vulnerable to Authentication Bypass in the Sales API in all versions up to, and including, 3.6.0.6. This is due to the API key lookup passing an empty api_key value to a meta query that then matches any existing API key instead of none. This makes it possible for unauthenticated attackers to pass the Sales API credential check and query its sales statistics endpoint (revenue, currency and order count), and it exposes the Sales API's 'period_compare' SQL Injection to unauthenticated attackers. The plugin creates a default API key during setup, so most installations are affected.

## References

- https://wpsec.com/vuln/WPSEC-2026-0524/
- https://plugins.svn.wordpress.org/tickera-event-ticketing-system/tags/3.6.0.7/
- https://wordpress.org/plugins/tickera-event-ticketing-system/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0524/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
