CVE-2025-67939
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67939 is a Missing Authorization (Broken Access Control) vulnerability in the Tickera WordPress plugin (tickera-event-ticketing-system) that allows authenticated attackers with low privileges to exploit incorrectly configured access control security levels. It affects all versions of the plugin through and including 3.5.6.2, with version 3.5.6.3 being the patched release. The vulnerability was reported on October 24, 2025, and published by Patchstack on January 16–22, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium), assigned by Patchstack (Patchstack).

Technical details

The root cause is CWE-862 (Missing Authorization), where one or more functions within the Tickera plugin fail to perform adequate authorization checks before executing privileged actions. This allows a low-privileged authenticated user (e.g., a Subscriber-level WordPress account) to invoke functionality that should be restricted to higher-privileged roles. The attack vector is network-based, requires low privileges, no user interaction, and low attack complexity, making it straightforward to exploit once an attacker has any valid WordPress account. The updated CVSS vector from Patchstack (April 2026) indicates the primary impact is on integrity (I:H), suggesting the vulnerability enables unauthorized data modification or privileged actions rather than just information disclosure (Patchstack).

Impact

Successful exploitation allows a low-privileged authenticated user to perform actions reserved for higher-privileged roles within the Tickera event ticketing system, with the primary impact being on integrity (unauthorized modification of data or plugin functionality). This could include manipulating event ticket data, orders, or plugin settings in ways not intended for subscriber-level users. While the scope is limited to the affected WordPress installation, compromise of ticketing data could have downstream business and reputational consequences for site operators (Patchstack).

Exploitability

There is no public evidence of active in-the-wild exploitation or weaponized exploit code at this time. The EPSS score is very low at approximately 0.017%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that broken access control vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Tickera plugin version 3.5.6.2 or earlier using tools like WPScan or by checking the plugin's readme.txt file at wp-content/plugins/tickera-event-ticketing-system/readme.txt.
  2. Obtain low-privileged access: Register or obtain credentials for a Subscriber-level (or equivalent low-privilege) WordPress account on the target site, which may be possible if user registration is open.
  3. Identify unprotected endpoints: Enumerate AJAX actions or REST API endpoints registered by the Tickera plugin that lack proper capability checks (e.g., via source code review of the plugin or fuzzing WordPress admin-ajax.php actions).
  4. Send unauthorized request: Craft and send an authenticated HTTP request (with valid nonce/cookie) to the vulnerable endpoint, invoking a privileged action such as modifying ticket data, event settings, or order records.
  5. Achieve unauthorized action: The server processes the request without verifying the user's role, resulting in unauthorized modification of ticketing system data (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated POST requests to wp-admin/admin-ajax.php with Tickera-specific action parameters from low-privileged user accounts; unexpected modifications to event or ticket records in the database.
  • File System: No specific file-based IOCs are expected for this access control vulnerability, as exploitation is purely request-based.
  • Database: Unexpected changes to Tickera-related database tables (e.g., ticket orders, event configurations) attributed to subscriber-level user IDs rather than administrator accounts.

Mitigation and workarounds

The vendor has released version 3.5.6.3 of the Tickera plugin, which patches this vulnerability. Site administrators should update the plugin to version 3.5.6.3 or later immediately via the WordPress plugin dashboard. As a temporary workaround, Patchstack users can enable the platform's virtual patching/mitigation rule to block exploitation attempts until the plugin is updated. Restricting open user registration on the WordPress site can also reduce the attack surface by limiting who can obtain the low-privileged account required for exploitation (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management