Description
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
Published: 2026-08-13
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated broken access control flaw in the WordPress Taxi Booking Manager for WooCommerce plugin, allowing an attacker to bypass the plugin’s authorization checks and use any functionality that should be restricted to authenticated users. This could enable attackers to gain access to sensitive data, alter booking settings, or otherwise interfere with the booking process, compromising both confidentiality and integrity of the system.

Affected Systems

The Taxi Booking Manager for WooCommerce plugin from MagePeopleTeam is affected. Versions 2.0.3 and earlier contain the flaw. Sites running these versions must upgrade to at least 2.0.5.

Risk and Exploitability

The CVSS base score of 7.5 denotes high severity. No EPSS score is available, so the precise likelihood of exploitation cannot be quantified. The flaw is not listed in the CISA KEV catalog. The most likely attack vector is remote, over HTTP/HTTPS, and requires no authentication because the vulnerability permits unauthenticated users to access protected plugin operations.

Generated by OpenCVE AI on August 13, 2026 at 17:26 UTC.

Remediation

Vendor Solution

Update the WordPress Taxi Booking Manager for WooCommerce Plugin to the latest available version (at least 2.0.5).


OpenCVE Recommended Actions

  • Update the Taxi Booking Manager for WooCommerce plugin to version 2.0.5 or later.
  • Restrict access to the plugin’s administrative endpoints so that only users with the required role can invoke them, using role management plugins or custom WordPress functions.
  • Audit the website logs for any suspicious requests to the plugin’s URLs and confirm that they are blocked or require authentication.

Generated by OpenCVE AI on August 13, 2026 at 17:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Magepeople
Magepeople taxi Booking Manager For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Magepeople
Magepeople taxi Booking Manager For Woocommerce
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
Title WordPress Taxi Booking Manager for WooCommerce plugin <= 2.0.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Magepeople Taxi Booking Manager For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:13:59.416Z

Reserved: 2026-02-19T09:51:35.297Z

Link: CVE-2026-27345

cve-icon Vulnrichment

Updated: 2026-08-13T15:13:53.090Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T14:16:55.847

Modified: 2026-08-14T19:09:20.713

Link: CVE-2026-27345

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:15:45Z

Weaknesses