Description
WordPress Plugin Tickera-WordPress Event Ticketing is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Tickera-WordPress Event Ticketing version 3.4.9.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.5.1.0 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:06E1BE38-FC1A-4799-A006-556B678AE701
https://plugins.svn.wordpress.org/tickera-event-ticketing-system/trunk/readme.txt