PT-2026-60432 · WordPress · Tickera
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Tickera – Sell Tickets & Manage Events versions prior to 3.6.0.1
Description
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. Authenticated attackers with contributor-level access or higher can inject arbitrary web scripts through the
price wrapper shortcode attribute. These scripts execute when a user visits the affected page, provided the victim has the referenced ticket ID in their cart cookie, meaning the payload only triggers for users who previously added that specific ticket to their cart.Recommendations
Update Tickera – Sell Tickets & Manage Events to version 3.6.0.1 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tickera