Impact
The Tickera – Sell Tickets & Manage Events plugin for WordPress contains an SQL injection vulnerability in the 's' parameter in all versions up to and including 3.6.0.0. The lack of proper escaping and preparation on the existing SQL query makes the flaw an instance of CWE‑89: Improper Validation or Sanitization Leading to SQL Injection. Authenticated users with staff or higher privileges can inject additional SQL statements, allowing them to retrieve sensitive data from the database and thereby compromise confidentiality.
Affected Systems
The affected product is the Tickera plugin for WordPress, versions up to and including 3.6.0.0. All installations of Tickera within that version range are vulnerable if the 's' parameter is used.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests low likelihood of current exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires authenticated access at the staff or higher level, so an attacker that has such credentials can execute arbitrary SQL and extract sensitive information.
OpenCVE Enrichment