Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.
Published: 2026-10-10
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Blind SQL Injection
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is an improper neutralization of special elements used in an SQL command, which permits a blind SQL injection attack. This flaw allows an attacker to supply crafted input that will be inserted into a database query, potentially extracting or modifying sensitive data stored in the site’s database. The weakness is a classic SQL Injection flaw (CWE‑89) that can compromise data confidentiality and, if further abused, could lead to additional attacks.

Affected Systems

All versions of the Tickera event ticketing system plugin for WordPress up to and including 3.6.0.6 are affected. The vendor is Tickera and the product is the Tickera plugin, which is installed on WordPress sites to manage event ticket sales.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical severity. The EPSS score is not available, and the vulnerability is not listed in the KEV catalog, but the high severity remains unchanged. The likely attack vector is via the plugin’s user-facing ticket forms or administrative interfaces that accept input data; an attacker can send malicious payloads that are incorporated into SQL statements without proper escaping. Because the injection is blind, detection may rely on timing or error responses, but once exploited the attacker could retrieve, delete, or alter database contents.

Generated by OpenCVE AI on October 10, 2026 at 18:21 UTC.

Remediation

Vendor Solution

Update the WordPress Tickera plugin to the latest available version (at least 3.6.0.7).


OpenCVE Recommended Actions

  • Update the Tickera plugin to version 3.6.0.7 or later
  • Restrict access to the plugin’s administrative areas to trusted users only
  • Monitor database query logs for abnormal or failed query patterns

Generated by OpenCVE AI on October 10, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.
Title WordPress Tickera plugin <= 3.6.0.6 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T17:00:10.991Z

Reserved: 2026-10-06T00:18:26.658Z

Link: CVE-2026-105889

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T17:17:00.063

Modified: 2026-10-10T17:17:00.063

Link: CVE-2026-105889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T18:30:08Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')