← Terug naar overzicht

A PHP Object Injection vulnerability has been identified in the Tickera WordPress plugin affecting versions up to and including 3.6.0.2. The vulnerability is unauthenticated, meaning attackers do not need any credentials to exploit it. PHP Object Injection vulnerabilities can allow attackers to perform various malicious actions depending on available PHP classes, potentially including remote code execution, file manipulation, or privilege escalation. The vulnerability has been reported via NVD and documented by Patchstack. Users of the Tickera event ticketing system plugin should update to a patched version immediately. The issue highlights risks associated with improper deserialization of user-supplied data in WordPress plugins.

Affected products

  • Tickera WordPress Plugin <= 3.6.0.2

Related CVE's

  • CVE-2026-82226

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities