Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2024-12578
Disclosure Date: December 14, 2024 (last updated December 18, 2024)
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.5.4.8 via the 'tickera_tickets_info' endpoint. This makes it possible for unauthenticated attackers to extract sensitive data from bookings like full names, email addresses, check-in/out timestamps and more.
0
Attacker Value
Unknown
CVE-2023-23726
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Tickera.com Tickera allows Cross Site Request Forgery.This issue affects Tickera: from n/a through 3.5.1.0.
0
Attacker Value
Unknown
CVE-2024-10263
Disclosure Date: November 05, 2024 (last updated November 09, 2024)
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
0
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2024-5860
Disclosure Date: June 18, 2024 (last updated July 06, 2024)
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tc_dl_delete_tickets AJAX action in all versions up to, and including, 3.5.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete all tickets associated with events.
0
Attacker Value
Unknown
CVE-2024-35729
Disclosure Date: June 10, 2024 (last updated June 13, 2024)
Missing Authorization vulnerability in Tickera.This issue affects Tickera: from n/a through 3.5.2.6.
0
Attacker Value
Unknown
CVE-2023-7252
Disclosure Date: April 22, 2024 (last updated April 22, 2024)
The Tickera WordPress plugin before 3.5.2.5 does not prevent users from leaking other users' tickets.
0
Attacker Value
Unknown
CVE-2022-4549
Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Tickera WordPress plugin before 3.5.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.
0
Attacker Value
Unknown
CVE-2021-24797
Disclosure Date: December 27, 2021 (last updated October 07, 2023)
The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events before outputting them in the Orders admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.
0