Impact
A missing authorization flaw in the Taxi Booking Manager for WooCommerce plugin allows an attacker to access and manipulate booking-related functions that should be restricted to authorized users. The vulnerability is identified as CWE‑862 and can enable unauthorized users to perform actions such as creating, editing, or deleting bookings within the system.
Affected Systems
WordPress plugin Taxi Booking Manager for WooCommerce, released by magepeopleteam. Versions from the initial release through 1.2.1 are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% shows a very low probability of widespread exploitation at the time of analysis. It is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves web-based interaction with the plugin’s administrative interfaces or API endpoints exposed to authenticated or unauthenticated users.
OpenCVE Enrichment
EUVD