Description
WordPress Plugin My Tickets is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently bypass completing payment. WordPress Plugin My Tickets version 1.9.11 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.9.12 or latest
References
Related Vulnerabilities
WordPress Plugin MetaSlider Cross-Site Scripting (3.17.1)
WordPress Plugin Real Estate Website Builder 'ajax_action' Parameter Cross-Site Scripting (0.1.0)
WebLogic CVE-2020-14639 Vulnerability (CVE-2020-14639)
WordPress Plugin Share Buttons by AddThis Cross-Site Request Forgery (5.3.5)
Drupal Improper Authentication Vulnerability (CVE-2010-3091)