# Tickera – Sell Tickets & Manage Events <= 3.6.0.6 - Unauthenticated Payment Bypass via 2Checkout IPN Handler

- **ID:** WPSEC-2026-0525
- **Plugin:** Tickera – Sell Tickets & Manage Events (`tickera-event-ticketing-system`), https://wordpress.org/plugins/tickera-event-ticketing-system/
- **Affected versions:** all versions before 3.6.0.7
- **Fixed in:** 3.6.0.7 (Update to 3.6.0.7 or later.)
- **Severity:** Medium 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
- **Weakness:** CWE-347
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/tickera-event-ticketing-system
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0525/

## Description

The Tickera plugin for WordPress is vulnerable to Payment Bypass in its 2Checkout gateway in all versions up to, and including, 3.6.0.6. This is due to 2Checkout signature verification not binding the signed sale and invoice identifiers to the order being marked as paid or to that order's total, accepting legacy signature formats and any non-empty seller ID, and the order confirmation callback marking the order named in the URL as paid whenever valid signature data for any transaction was supplied. This makes it possible for unauthenticated attackers who complete one genuine 2Checkout payment to reuse its signature data to have other unpaid orders marked as paid, when the 2Checkout gateway is enabled and configured.

## References

- https://wpsec.com/vuln/WPSEC-2026-0525/
- https://plugins.svn.wordpress.org/tickera-event-ticketing-system/tags/3.6.0.7/
- https://wordpress.org/plugins/tickera-event-ticketing-system/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0525/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
