


Perceptive Security
SOC/SIEM Consultancy

Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
Published:
31 augustus 2026 om 00:00:00
Alert date:
1 september 2026 om 00:05:29
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
A PHP Object Injection vulnerability has been identified in the Tickera WordPress plugin affecting versions up to and including 3.6.0.2. The vulnerability is unauthenticated, meaning attackers do not need any credentials to exploit it. PHP Object Injection vulnerabilities can allow attackers to perform various malicious actions depending on available PHP classes, potentially including remote code execution, file manipulation, or privilege escalation. The vulnerability has been reported via NVD and documented by Patchstack. Users of the Tickera event ticketing system plugin should update to a patched version immediately. The issue highlights risks associated with improper deserialization of user-supplied data in WordPress plugins.
Technical details
Mitigation steps:
Affected products:
Tickera WordPress Plugin <= 3.6.0.2
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82226
https://patchstack.com/database/wordpress/plugin/tickera-event-ticketing-system/vulnerability/wordpress-tickera-plugin-3-6-0-2-php-object-injection-vulnerability?_s_id=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
