WordPress Plugin Vulnerabilities

Tickera – WordPress Event Ticketing < 3.5.4.9 - Unauthenticated Customer Data Exposure

Description

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.5.4.8 via the 'tickera_tickets_info' endpoint. This makes it possible for unauthenticated attackers to extract sensitive data from bookings like full names, email addresses, check-in/out timestamps and more.

Affects Plugins

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Paule, Aaron Schlitt
Verified
No

Timeline

Publicly Published
2024-12-13 (about 1 year ago)
Added
2024-12-13 (about 1 year ago)
Last Updated
2025-01-17 (about 1 year ago)

Other