{
 "id": "WPSEC-2026-0525",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0525/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0525/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0525/index.md",
 "title": "Tickera – Sell Tickets & Manage Events <= 3.6.0.6 - Unauthenticated Payment Bypass via 2Checkout IPN Handler",
 "description": "The Tickera plugin for WordPress is vulnerable to Payment Bypass in its 2Checkout gateway in all versions up to, and including, 3.6.0.6. This is due to 2Checkout signature verification not binding the signed sale and invoice identifiers to the order being marked as paid or to that order's total, accepting legacy signature formats and any non-empty seller ID, and the order confirmation callback marking the order named in the URL as paid whenever valid signature data for any transaction was supplied. This makes it possible for unauthenticated attackers who complete one genuine 2Checkout payment to reuse its signature data to have other unpaid orders marked as paid, when the 2Checkout gateway is enabled and configured.",
 "plugin": {
  "slug": "tickera-event-ticketing-system",
  "name": "Tickera – Sell Tickets & Manage Events",
  "full_name": "Tickera – Sell Tickets & Manage Events",
  "wordpress_org": "https://wordpress.org/plugins/tickera-event-ticketing-system/",
  "advisories_url": "https://wpsec.com/vuln/plugin/tickera-event-ticketing-system/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/tickera-event-ticketing-system"
 },
 "type": "AUTHBYPASS",
 "cwe": [
  "CWE-347"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.9,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "3.6.0.7",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 3.6.0.7"
  ]
 },
 "introduced_in": null,
 "fixed_in": "3.6.0.7",
 "remediation": "Update to 3.6.0.7 or later.",
 "fix_released": "2026-10-06T12:17:22+00:00",
 "published": "2026-10-07T12:46:23+00:00",
 "updated": "2026-10-07T11:59:32.979240+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0525/",
  "https://plugins.svn.wordpress.org/tickera-event-ticketing-system/tags/3.6.0.7/",
  "https://wordpress.org/plugins/tickera-event-ticketing-system/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/tickera-event-ticketing-system",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}