Description
WordPress Plugin Tickera-WordPress Event Ticketing is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Tickera-WordPress Event Ticketing version 3.4.9.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.5.1.0 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:06E1BE38-FC1A-4799-A006-556B678AE701
https://plugins.svn.wordpress.org/tickera-event-ticketing-system/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Joy Of Text Lite-SMS messaging for WordPress SQL Injection (2.3.0)
Chamilo Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-4224)
WordPress Plugin Mail Subscribe List Unspecified Vulnerability (2.0.9)
Microsoft SQL Server CVE-2023-36420 Vulnerability (CVE-2023-36420)