CVE-2026-82226: WordPress Tickera plugin <= 3.6.0.2 - PHP Object Injection vulnerability
Published Aug 31, 2026
·Updated
Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
Affected Software
0 affected components
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Tickera Pluginto a version that resolves this vulnerability.Fixed in 3.6.0.3
Event History
Aug 31, 2026
CVE Published
via MITRE·08:30 PM
Data Sourced
via MITRE·08:30 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation.
2
What is the potential impact of a successful exploit?
The vulnerability is rated critical with high confidentiality, integrity, and availability impact. A successful exploit could therefore affect data secrecy, modification, and service availability.
3
Which Tickera versions are affected?
Tickera versions 3.6.0.2 and earlier are identified as affected.