SQL Injection Vulnerability in Tickera Ticketing Plugin for WordPress
CVE-2026-15448
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 July 2026
What is CVE-2026-15448?
The Tickera β Sell Tickets & Manage Events plugin for WordPress has a security flaw that allows authenticated attackers with staff-level access to exploit an SQL Injection vulnerability. This occurs through the 'tc_order_status_filter' parameter, where inadequate escaping of user input and poor query preparation can lead to the execution of unauthorized SQL commands. As a result, sensitive data can be extracted from the database, potentially compromising user information and overall site security.
Affected Version(s)
Tickera β Sell Tickets & Manage Events 0 <= 3.6.0.1