CVE-2024-35729: WordPress Tickera plugin <= 3.5.2.6 - Broken Access Control vulnerability
Published Jun 10, 2024
·Updated
Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tickera: from n/a through <= 3.5.2.6.
Affected Software
1 affected component
Tickera Tickera WordPress<3.5.2.7
Remediation
Information
Update to 3.5.2.7 or a higher version.
Event History
Jun 10, 2024
CVE Published
via MITRE·07:44 AM
Data Sourced
via MITRE·07:44 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35729?
CVE-2024-35729 is classified with a high severity due to its missing authorization vulnerabilities.
2
How do I fix CVE-2024-35729?
To fix CVE-2024-35729, update Tickera to version 3.5.2.7 or later immediately.
3
What software versions are affected by CVE-2024-35729?
CVE-2024-35729 affects all versions of Tickera prior to 3.5.2.7.
4
What kind of vulnerability is CVE-2024-35729?
CVE-2024-35729 is a missing authorization vulnerability, which can lead to unauthorized access.
5
What risks are associated with CVE-2024-35729?
The risks associated with CVE-2024-35729 include potential unauthorized actions by users who should not have access.