CVE-2025-12356: falha de média gravidade em Tickera – Sell Tickets & Manage Events
Tickera – WordPress Event Ticketing <= 3.5.6.4 - Missing Authorization to Authenticated (Subscriber+) Event/Post Status Update
Publicada em · Atualizada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 4.3epss 0.3%
probabilidade de exploração
0.3%top 85% das CVEs
exploração observada
nãonenhuma fonte reporta
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_change_ticket_status' AJAX endpoint in all versions up to, and including, 3.5.6.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update post/event statuses.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Produtos afetados
tickera · Tickera – Sell Tickets & Manage EventsCVEs relacionadas — Tickera – Sell Tickets & Manage Events
No mesmo produto, das mais perigosas para as menos.
CVE-2024-10263HIGHTickera – WordPress Event Ticketing <= 3.5.4.4 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.5%CVE-2024-12578MEDIUMTickera – WordPress Event Ticketing <= 3.5.4.8 - Unauthenticated Customer Data ExposureEPSS 0.5%CVE-2026-15761MEDIUMTickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_event_filter' ParameterEPSS 0.5%CVE-2022-4974MEDIUMFreemius SDK <= 2.4.2 - Missing Authorization ChecksEPSS 0.4%CVE-2026-15448MEDIUMTickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_order_status_filter' ParameterEPSS 0.4%CVE-2026-13754MEDIUMTickera <= 3.6.0.0 - Authenticated (Staff+) SQL Injection via 's' ParameterEPSS 0.4%