Impact
The vulnerability exists in versions of the Taxi Booking Manager for WooCommerce plugin older than 2.0.8. It is an unauthenticated broken access control flaw (CWE‑862) that permits an attacker to invoke privileged booking management functions without providing valid user credentials. Depending on the exposed functionality, this could lead to unauthorized creation, cancellation, or modification of taxi bookings, thereby compromising data integrity and potentially exposing sensitive customer information.
Affected Systems
The affected product is the WordPress Taxi Booking Manager for WooCommerce plugin developed by magepeopleteam. Vulnerable versions are any release prior to 2.0.8. WordPress sites using this plugin and not yet updated to 2.0.8 or newer are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity; the EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers could exploit the flaw by sending unauthenticated HTTP requests targeting the plugin’s booking management endpoints. This attack vector does not require user authentication or elevated privileges, allowing unauthenticated users to manipulate booking records or access sensitive data.
OpenCVE Enrichment