Description
Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
Published: 2026-08-31
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated PHP Object Injection flaw in the Tickera WordPress plugin versions 3.6.0.2 and earlier, as stated in the official description. It is inferred that attackers can supply crafted serialized PHP objects through the plugin’s input handling, which may lead to arbitrary code execution on the server and compromise the website’s confidentiality, integrity, and availability. This flaw is identified as CWE-502.

Affected Systems

WordPress sites running the Tickera event ticketing system plugin before version 3.6.0.3 are affected. The vulnerability is present in all releases up to and including 3.6.0.2. The affected component is the Tickera plugin component within the WordPress environment.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. Based on the description, it is inferred that the attack vector is remote and unauthenticated, meaning an attacker only needs network access to craft malicious requests. The EPSS is not listed, and the vulnerability is not in the CISA KEV catalog, but the high CVSS and the ability to reach the server freely make exploitation likely. A successful exploit would give the attacker remote code execution privileges on the hosting environment.

Generated by OpenCVE AI on August 31, 2026 at 21:54 UTC.

Remediation

Vendor Solution

Update the WordPress Tickera Plugin to the latest available version (at least 3.6.0.3).


OpenCVE Recommended Actions

  • Update the Tickera plugin to version 3.6.0.3 or a newer release.
  • Ensure that the plugin’s endpoints are protected by proper authentication to prevent unauthenticated access.
  • If an update is unavailable, temporarily disable the Tickera plugin until the fix is applied.

Generated by OpenCVE AI on August 31, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Tickera
Tickera tickera
Wordpress
Wordpress wordpress
Vendors & Products Tickera
Tickera tickera
Wordpress
Wordpress wordpress

Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
Title WordPress Tickera plugin <= 3.6.0.2 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Tickera Tickera
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-31T20:30:54.958Z

Reserved: 2026-08-28T09:18:05.695Z

Link: CVE-2026-82226

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T21:17:53.447

Modified: 2026-08-31T21:17:53.447

Link: CVE-2026-82226

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T22:00:06Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data