Description
WordPress Plugin Tickera-WordPress Event Ticketing is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Tickera-WordPress Event Ticketing version 3.5.1.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.5.1.1 or latest
References
Related Vulnerabilities
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-1936)
WordPress Plugin Ad Invalid Click Protector (AICP) Malicious Code (1.2.9)
Joomla! Core 3.3.x Denial of Service (3.3.0 - 3.3.4)
WordPress Plugin DiveBook Multiple Vulnerabilities (1.1.4)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-12466)