Description
WordPress Plugin Tickera-WordPress Event Ticketing is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Tickera-WordPress Event Ticketing version 3.4.9.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.5.1.0 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:06E1BE38-FC1A-4799-A006-556B678AE701
https://plugins.svn.wordpress.org/tickera-event-ticketing-system/trunk/readme.txt
Related Vulnerabilities
Apache Tomcat Other Vulnerability (CVE-2011-2481)
Oracle JRE CVE-2013-2431 Vulnerability (CVE-2013-2431)
WordPress Plugin Social Essentials-Social Stats and Sharing Buttons Cross-Site Scripting (1.3.1)
PHP Improper Input Validation Vulnerability (CVE-2015-4598)
AbanteCart Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-26521)