
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67939 is a Missing Authorization (Broken Access Control) vulnerability in the Tickera WordPress plugin (tickera-event-ticketing-system) that allows authenticated attackers with low privileges to exploit incorrectly configured access control security levels. It affects all versions of the plugin through and including 3.5.6.2, with version 3.5.6.3 being the patched release. The vulnerability was reported on October 24, 2025, and published by Patchstack on January 16–22, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium), assigned by Patchstack (Patchstack).
The root cause is CWE-862 (Missing Authorization), where one or more functions within the Tickera plugin fail to perform adequate authorization checks before executing privileged actions. This allows a low-privileged authenticated user (e.g., a Subscriber-level WordPress account) to invoke functionality that should be restricted to higher-privileged roles. The attack vector is network-based, requires low privileges, no user interaction, and low attack complexity, making it straightforward to exploit once an attacker has any valid WordPress account. The updated CVSS vector from Patchstack (April 2026) indicates the primary impact is on integrity (I:H), suggesting the vulnerability enables unauthorized data modification or privileged actions rather than just information disclosure (Patchstack).
Successful exploitation allows a low-privileged authenticated user to perform actions reserved for higher-privileged roles within the Tickera event ticketing system, with the primary impact being on integrity (unauthorized modification of data or plugin functionality). This could include manipulating event ticket data, orders, or plugin settings in ways not intended for subscriber-level users. While the scope is limited to the affected WordPress installation, compromise of ticketing data could have downstream business and reputational consequences for site operators (Patchstack).
There is no public evidence of active in-the-wild exploitation or weaponized exploit code at this time. The EPSS score is very low at approximately 0.017%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that broken access control vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).
wp-content/plugins/tickera-event-ticketing-system/readme.txt.wp-admin/admin-ajax.php with Tickera-specific action parameters from low-privileged user accounts; unexpected modifications to event or ticket records in the database.The vendor has released version 3.5.6.3 of the Tickera plugin, which patches this vulnerability. Site administrators should update the plugin to version 3.5.6.3 or later immediately via the WordPress plugin dashboard. As a temporary workaround, Patchstack users can enable the platform's virtual patching/mitigation rule to block exploitation attempts until the plugin is updated. Restricting open user registration on the WordPress site can also reduce the attack surface by limiting who can obtain the low-privileged account required for exploitation (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."