Impact
Improper validation of the quantity field in the Taxi Booking Manager for WooCommerce plugin allows an attacker to manipulate booking data. The vulnerability can lead to unauthorized modification of booking amounts, potentially causing financial discrepancies or denial of service. The weakness is identified as CWE-1284, reflecting a failure to validate user input.
Affected Systems
The issue affects the WordPress Taxi Booking Manager for WooCommerce plugin released by Magepeople inc. Versions up to and including 2.1.1 are vulnerable. The plugin runs within WordPress sites that use WooCommerce as the e‑commerce platform.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower current exploitation probability. Based on the description, the likely attack vector is a web‑based request that submits an altered quantity value; the attack would require the ability to submit requests to the plugin’s form endpoint, which could be achieved from the client side or via authenticated sessions. Exploitation would allow manipulation of booking data but may not grant arbitrary code execution.
OpenCVE Enrichment