A vulnerability, which was classified as problematic, was found in Tickera Plugin up to 3.6.0.1 on WordPress. Affected is an unknown function. The manipulation of the argument tc_order_status_filter results in sql injection.
This vulnerability is cataloged as CVE-2026-15448. The attack may be launched remotely. There is no exploit available.