Impact
The vulnerability is an unauthenticated broken access control flaw in the WordPress Taxi Booking Manager for WooCommerce plugin, allowing an attacker to bypass the plugin’s authorization checks and use any functionality that should be restricted to authenticated users. This could enable attackers to gain access to sensitive data, alter booking settings, or otherwise interfere with the booking process, compromising both confidentiality and integrity of the system.
Affected Systems
The Taxi Booking Manager for WooCommerce plugin from MagePeopleTeam is affected. Versions 2.0.3 and earlier contain the flaw. Sites running these versions must upgrade to at least 2.0.5.
Risk and Exploitability
The CVSS base score of 7.5 denotes high severity. No EPSS score is available, so the precise likelihood of exploitation cannot be quantified. The flaw is not listed in the CISA KEV catalog. The most likely attack vector is remote, over HTTP/HTTPS, and requires no authentication because the vulnerability permits unauthenticated users to access protected plugin operations.
OpenCVE Enrichment