What is CVE-2026-15761?
This vulnerability is a generic SQL Injection in the "Tickera – Sell Tickets & Manage Events" plugin for WordPress up to version 3.6.0.1, affecting the 'tc_event_filter' parameter due to improper escaping and lack of SQL preparation. Immediate update to the latest patched version is recommended.
Azərbaycanca: Bu boşluq, WordPress üçün "Tickera – Sell Tickets & Manage Events" plagininin 3.6.0.1 versiyasına qədər olan bütün versiyalarında "tc_event_filter" parametri vasitəsilə SQL Injection zəifliyinə səbəb olur. Təcili olaraq plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the "Tickera – Sell Tickets & Manage Events" plugin are affected by the CVE-2026-15761 SQL Injection vulnerability?
This vulnerability exists in all versions of the plugin up to 3.6.0.1.
What action should be taken to mitigate the CVE-2026-15761 vulnerability?
It is recommended to immediately update the plugin to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.