Description
Improper Validation of Specified Quantity in Input vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Input Data Manipulation.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.1.1.
Published: 2026-10-05
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Input Data Manipulation via quantity field
Action: Patch Plugin
AI Analysis

Impact

Improper validation of the quantity field in the Taxi Booking Manager for WooCommerce plugin allows an attacker to manipulate booking data. The vulnerability can lead to unauthorized modification of booking amounts, potentially causing financial discrepancies or denial of service. The weakness is identified as CWE-1284, reflecting a failure to validate user input.

Affected Systems

The issue affects the WordPress Taxi Booking Manager for WooCommerce plugin released by Magepeople inc. Versions up to and including 2.1.1 are vulnerable. The plugin runs within WordPress sites that use WooCommerce as the e‑commerce platform.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower current exploitation probability. Based on the description, the likely attack vector is a web‑based request that submits an altered quantity value; the attack would require the ability to submit requests to the plugin’s form endpoint, which could be achieved from the client side or via authenticated sessions. Exploitation would allow manipulation of booking data but may not grant arbitrary code execution.

Generated by OpenCVE AI on October 5, 2026 at 10:23 UTC.

Remediation

Vendor Solution

Update the WordPress Taxi Booking Manager for WooCommerce plugin to the latest available version (at least 2.1.2).


OpenCVE Recommended Actions

  • Upgrade Taxi Booking Manager for WooCommerce to version 2.1.2 or later.
  • Implement server‑side validation that enforces quantity limits and legitimate booking rules.
  • Restrict quantity changes to authenticated users and apply CSRF protection for booking forms.
  • Consider monitoring booking data for anomalous quantity values after deployment.

Generated by OpenCVE AI on October 5, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
Description Improper Validation of Specified Quantity in Input vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Input Data Manipulation.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.1.1.
Title WordPress Taxi Booking Manager for WooCommerce plugin <= 2.1.1 - Other vulnerability Type vulnerability
Weaknesses CWE-1284
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T12:49:49.460Z

Reserved: 2026-09-30T12:43:33.093Z

Link: CVE-2026-103351

cve-icon Vulnrichment

Updated: 2026-10-05T12:49:42.005Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:06.693

Modified: 2026-10-05T13:16:50.600

Link: CVE-2026-103351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T10:30:18Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input