Tickera – Sell Tickets & Manage Events <= 3.6.0.6 - Unauthenticated Payment Bypass via 2Checkout IPN Handler

Medium 5.9 CWE-347Fixed in 3.6.0.7
ID
WPSEC-2026-0525
Plugin
Tickera – Sell Tickets & Manage Events (tickera-event-ticketing-system)
Affected
all versions before 3.6.0.7
Remediation
Update to 3.6.0.7 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness
CWE-347
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Tickera – Sell Tickets & Manage Events on WPSec AttackSurface
Fix released
Published

Description

The Tickera plugin for WordPress is vulnerable to Payment Bypass in its 2Checkout gateway in all versions up to, and including, 3.6.0.6. This is due to 2Checkout signature verification not binding the signed sale and invoice identifiers to the order being marked as paid or to that order's total, accepting legacy signature formats and any non-empty seller ID, and the order confirmation callback marking the order named in the URL as paid whenever valid signature data for any transaction was supplied. This makes it possible for unauthenticated attackers who complete one genuine 2Checkout payment to reuse its signature data to have other unpaid orders marked as paid, when the 2Checkout gateway is enabled and configured.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0