Description
Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions.
Published: 2026-10-01
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Data Access via IDOR
Action: Patch Immediately
AI Analysis

Impact

The Bus Ticket Booking with Seat Reservation WordPress plugin suffers from an unauthenticated Insecure Direct Object Reference flaw that allows attackers to tamper with request parameters and access protected reservation data. Because the vulnerability does not require prior authentication, an attacker can view or modify booking details, leading to potential data leakage, tampering of seat allocations, and operational disruption. The underlying weakness is captured by CWE‑639, which highlights inadequate protection of object identifiers in request handling.

Affected Systems

WordPress users who have installed the Bus Ticket Booking with Seat Reservation plugin by MagePeopleTeam, versions up to and including 5.9.3. The plugin provides seat reservation functionality for event and transportation booking sites running on WordPress. Users running any of these vulnerable versions are exposed until they upgrade to 5.9.4 or later.

Risk and Exploitability

The CVSS score of 6.5 marks the issue as medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation campaigns yet. However, the attack path is straightforward—an attacker sends crafted payloads that substitute resource identifiers in URLs or form fields, requiring no credentials. Consequently, the risk is elevated for sites that expose the plugin’s booking endpoints to public users or untrusted actors. Given the moderate CVSS rating and the absence of exploitation data, administrators should treat the vulnerability as a medium‑risk weakness and address it promptly. In the absence of a public exploit, potential attackers still could discover and leverage the IDOR by simple request modification tools.

Generated by OpenCVE AI on October 1, 2026 at 15:58 UTC.

Remediation

Vendor Solution

Update the WordPress Bus Ticket Booking with Seat Reservation plugin to the latest available version (at least 5.9.4).


OpenCVE Recommended Actions

  • Upgrade to the latest version of the Bus Ticket Booking with Seat Reservation plugin (5.9.4 or newer).
  • Verify that only users with appropriate roles (e.g., administrators or editors) can access booking modification pages and APIs.
  • Audit the plugin’s request handling to ensure that resource identifiers are validated against the current user’s permissions before any action is taken.

Generated by OpenCVE AI on October 1, 2026 at 15:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions.
Title WordPress Bus Ticket Booking with Seat Reservation plugin <= 5.9.3 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-01T15:02:09.768Z

Reserved: 2026-09-24T10:23:10.130Z

Link: CVE-2026-97251

cve-icon Vulnrichment

Updated: 2026-10-01T15:02:00.848Z

cve-icon NVD

Status : Received

Published: 2026-10-01T15:17:37.470

Modified: 2026-10-01T15:17:37.470

Link: CVE-2026-97251

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T16:00:11Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key