Executive brief
A security flaw exists in the Taxi Booking Manager for WooCommerce plugin, which is used by WordPress sites to manage transportation reservations. Due to incorrect access controls, unauthorized individuals may be able to access information or perform actions that should be restricted to administrators. This could lead to the exposure of booking details or unauthorized changes to the booking system.
Technical details
The Taxi Booking Manager for WooCommerce plugin for WordPress is vulnerable to broken access control (CWE-862) in versions up to and including 2.0.1. The vulnerability stems from missing authorization checks or incorrectly configured security levels within the plugin's functional components. An unauthenticated remote attacker can exploit this flaw to bypass intended access restrictions, potentially leading to unauthorized data retrieval or the execution of restricted administrative functions. The issue is resolved in version 2.0.2.
Affected products
- Magepeople inc. Taxi Booking Manager for WooCommerce n/a through 2.0.1
Timeline
- 2025-12-28: other: Reported by researcher Bao - BlueRock
- 2026-05-26: advisory: Published by Patchstack and NVD
- 2026-05-26: patched: Version 2.0.2 released to address the vulnerability