Impact
This vulnerability allows an attacker to bypass the plugin’s authentication mechanism by using an alternate path or channel. The flaw means that, without proper credentials, an unauthorized user could potentially obtain access to the Taxi Booking Manager’s privileged functions, which may include booking management, customer information, and potentially other subsystems within the WordPress site. The impact is a loss of confidentiality and integrity for sensitive data handled by the plugin, and it could serve as a foothold for further exploitation if the attacker can then use the plugin’s administrative interfaces to manipulate site content or user accounts. The weakness is a classic authentication bypass (CWE‑288) and does not involve arbitrary code execution or privilege escalation beyond the plugin’s own capabilities.
Affected Systems
The vulnerability affects all instances of the Taxi Booking Manager for WooCommerce plugin from Magepeople inc. that are at version earlier than 2.0.8. Any deployment using a pre‑2.0.8 release is susceptible; versions 2.0.8 and later are not affected.
Risk and Exploitability
The CVSS score of 7.3 reflects a high likelihood of exploitation in a realistic environment. While the EPSS score is not available, the absence of a KEV listing suggests that large‑scale, publicly known exploitation has not yet been documented. The attack vector is remote, inferred from the nature of a WordPress plugin that can be accessed over the web; the breach requires only that an attacker can reach the plugin’s endpoints, which is typically possible for anyone with internet access to the site.
OpenCVE Enrichment