CRITICAL
9.8 CVE-2026-82226 Published 31 Aug 2026
Tickera Event Ticketing Plugin PHP Object Injection
Worried this affects one of your servers?
Tickera, a popular event ticketing plugin for WordPress, is affected by an unauthenticated PHP Object Injection vulnerability in versions up to 3.6.0.2.
This vulnerability allows attackers to inject malicious PHP objects, potentially leading to remote code execution.
- Affected versions: Tickera up to 3.6.0.2
- Impact: Unauthenticated PHP Object Injection, potential remote code execution
Reference: CVE-2026-82226 on NVD
← Back to Security News