Impact
The vulnerability is an unauthenticated PHP Object Injection flaw in the Tickera WordPress plugin versions 3.6.0.2 and earlier, as stated in the official description. It is inferred that attackers can supply crafted serialized PHP objects through the plugin’s input handling, which may lead to arbitrary code execution on the server and compromise the website’s confidentiality, integrity, and availability. This flaw is identified as CWE-502.
Affected Systems
WordPress sites running the Tickera event ticketing system plugin before version 3.6.0.3 are affected. The vulnerability is present in all releases up to and including 3.6.0.2. The affected component is the Tickera plugin component within the WordPress environment.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. Based on the description, it is inferred that the attack vector is remote and unauthenticated, meaning an attacker only needs network access to craft malicious requests. The EPSS is not listed, and the vulnerability is not in the CISA KEV catalog, but the high CVSS and the ability to reach the server freely make exploitation likely. A successful exploit would give the attacker remote code execution privileges on the hosting environment.
OpenCVE Enrichment