Impact
The Tickera plugin contains a stored cross‑site scripting flaw in the ‘price_wrapper’ shortcode attribute, allowing an authenticated contributor to insert malicious scripts that are stored in the database. When a user with the referenced ticket ID accesses a page containing the shortcode, the injected script executes in that user's browser, potentially enabling session hijacking, cookie theft, or defacement for those particular users. This vulnerability stems from the failure to sanitize user input and encode output, as captured by CWE‑79.
Affected Systems
The issue affects the Tickera – Sell Tickets & Manage Events WordPress plugin for all releases up to and including 3.6.0.0. Any WordPress site that incorporates these versions of the plugin is susceptible to the vulnerability, impacting event organizers who use Tickera to sell tickets on public‑facing sites.
Risk and Exploitability
With a CVSS score of 6.4 and an EPSS below 1%, the risk is moderate and the exploitation likelihood is low. The attack requires contributor‑level access, meaning an attacker must first gain or possess such permissions. The vulnerability is not listed in the CISA KEV catalog, and the payload only affects users who have the ticket ID present in their cart cookie, limiting the impact to a subset of visitors.
OpenCVE Enrichment