
My Tickets – Accessible Event Ticketing Security & Risk Analysis
wordpress.org/plugins/my-ticketsMy Tickets is a simple, flexible platform for selling event tickets with WordPress.
Is My Tickets – Accessible Event Ticketing Safe to Use in 2026?
Generally Safe
Score 92/100My Tickets – Accessible Event Ticketing has a strong security track record. Known vulnerabilities have been patched promptly.
This plugin, "my-tickets" v2.1.2, exhibits a mixed security posture. While it demonstrates good practices in areas like using prepared statements for SQL queries and proper output escaping, several concerns warrant attention. The presence of two AJAX handlers without authentication checks presents a direct attack vector. The taint analysis reveals six high-severity flows with unsanitized paths, indicating potential vulnerabilities in how user-supplied data is processed. Furthermore, the plugin's history of eight CVEs, including a high-severity one for improper authorization and medium-severity ones covering cross-site scripting and information exposure, suggests a recurring pattern of security weaknesses that attackers could exploit. While the absence of unpatched CVEs and critical taint flows is positive, the combination of unprotected entry points, high-severity taint flows, and past vulnerability trends indicates a moderate to high risk.
Key Concerns
- Two AJAX handlers without auth checks
- Six high severity taint flows
- History of 8 CVEs including 1 high severity
- 12 flows with unsanitized paths
My Tickets – Accessible Event Ticketing Security Vulnerabilities
CVEs by Year
Severity Breakdown
8 total CVEs
My Tickets – Accessible Event Ticketing <= 2.1.0 - Unauthenticated Information Exposure
My Tickets <= 2.1.0 - Missing Authorization
My Tickets <= 2.0.22 - Authenticated (Contributor+) Stored Cross-Site Scripting
My Tickets – Accessible Event Ticketing <= 2.0.16 - Authenticated (Subscriber+) Privilege Escalation
My Tickets <= 2.0.9 - Missing Authorization
My Tickets <= 1.9.11 - Authorization Bypass
My Tickets <= 1.9.10 - Cross-Site Request Forgery
My Tickets <= 1.8.30 - Unauthenticated Stored Cross-Site Scripting
My Tickets – Accessible Event Ticketing Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
My Tickets – Accessible Event Ticketing Attack Surface
AJAX Handlers 10
Shortcodes 6
WordPress Hooks 121
Scheduled Events 1
Maintenance & Trust
My Tickets – Accessible Event Ticketing Maintenance & Trust
Maintenance Signals
Community Trust
My Tickets – Accessible Event Ticketing Alternatives
Event Tickets and Registration
event-tickets
Event Tickets allows your visitors to RSVP and buy tickets to events on your site. Also works seamlessly with The Events Calendar.
Ticket Tailor — Event Ticketing & Registration
ticket-tailor
Sell event tickets online via your WordPress website. Ticket Tailor is an easy event ticketing & event registration system.
Tickera – Sell Tickets & Manage Events
tickera-event-ticketing-system
Sell tickets, manage events, and handle event registration on your site — PDF tickets, QR/Barcode check-in, and seamless ticket sales for WordPress.
Event Espresso – Event Registration & Ticketing Sales
event-espresso-decaf
The best events plugin with event registration, free and paid ticket sales, event registration forms, PayPal payments, automatic emails, and more!
Extended Shortcodes for Ultimate Membership Pro
extended-shortcodes-for-ultimate-membership-pro
Extend Ultimate Membership Pro functionality with a list of shortcodes which can be used by admin in order to manage content restriction.
My Tickets – Accessible Event Ticketing Developer Profile
6 plugins · 96K total installs
How We Detect My Tickets – Accessible Event Ticketing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/my-tickets/css/style.css/wp-content/plugins/my-tickets/css/jquery.timepicker.css/wp-content/plugins/my-tickets/js/my-tickets.js/wp-content/plugins/my-tickets/js/jquery.timepicker.min.js/wp-content/plugins/my-tickets/js/datetime.js/wp-content/plugins/my-tickets/js/admin.js/wp-content/plugins/my-tickets/js/my-tickets.js/wp-content/plugins/my-tickets/js/jquery.timepicker.min.js/wp-content/plugins/my-tickets/js/datetime.js/wp-content/plugins/my-tickets/js/admin.jsmy-tickets/style.css?ver=my-tickets/css/style.css?ver=my-tickets/css/jquery.timepicker.css?ver=my-tickets/js/my-tickets.js?ver=my-tickets/js/jquery.timepicker.min.js?ver=my-tickets/js/datetime.js?ver=my-tickets/js/admin.js?ver=HTML / DOM Fingerprints
mt-admin-noticemt-playground-noticemy_tickets_settings