Impact
The vulnerability is an improper neutralization of special elements used in an SQL command, which permits a blind SQL injection attack. This flaw allows an attacker to supply crafted input that will be inserted into a database query, potentially extracting or modifying sensitive data stored in the site’s database. The weakness is a classic SQL Injection flaw (CWE‑89) that can compromise data confidentiality and, if further abused, could lead to additional attacks.
Affected Systems
All versions of the Tickera event ticketing system plugin for WordPress up to and including 3.6.0.6 are affected. The vendor is Tickera and the product is the Tickera plugin, which is installed on WordPress sites to manage event ticket sales.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. The EPSS score is not available, and the vulnerability is not listed in the KEV catalog, but the high severity remains unchanged. The likely attack vector is via the plugin’s user-facing ticket forms or administrative interfaces that accept input data; an attacker can send malicious payloads that are incorporated into SQL statements without proper escaping. Because the injection is blind, detection may rely on timing or error responses, but once exploited the attacker could retrieve, delete, or alter database contents.
OpenCVE Enrichment