CVE-2026-105889: WordPress Tickera plugin <= 3.6.0.6 - SQL Injection vulnerability
Published Oct 10, 2026
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.
Affected Software
1 affected component
Tickera Tickera Event Ticketing System<=3.6.0.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Tickera pluginto a version that resolves this vulnerability.Fixed in 3.6.0.7
Event History
Oct 10, 2026
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Can an attacker exploit this without a WordPress account or user interaction?
The CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
2
What is the expected security impact if exploitation succeeds?
The rating indicates high confidentiality impact and low availability impact. The integrity impact is rated as none, and the scope is changed.