Description
WordPress Plugin My Tickets is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently bypass completing payment. WordPress Plugin My Tickets version 1.9.11 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.9.12 or latest
References
Related Vulnerabilities
WordPress 3.3.1 Multiple Vulnerabilities (2.0 - 3.3.1)
WordPress Plugin WP-Polls Cross-Site Scripting (2.73)
WordPress Plugin Download Zip Attachments Arbitrary File Download (1.0.0)
WordPress Plugin eCommerce Product Catalog for WordPress Cross-Site Request Forgery (3.0.17)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-16633)