top of page
perceptive_background_267k.jpg

Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

Published:

31 augustus 2026 om 00:00:00

Alert date:

1 september 2026 om 00:05:29

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

A PHP Object Injection vulnerability has been identified in the Tickera WordPress plugin affecting versions up to and including 3.6.0.2. The vulnerability is unauthenticated, meaning attackers do not need any credentials to exploit it. PHP Object Injection vulnerabilities can allow attackers to perform various malicious actions depending on available PHP classes, potentially including remote code execution, file manipulation, or privilege escalation. The vulnerability has been reported via NVD and documented by Patchstack. Users of the Tickera event ticketing system plugin should update to a patched version immediately. The issue highlights risks associated with improper deserialization of user-supplied data in WordPress plugins.

Technical details

Mitigation steps:

Affected products:

Tickera WordPress Plugin <= 3.6.0.2

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page