Junglewise Threat Intelligence

CVE-2026-93928: Magepeople Taxi Booking Manager for WooCommerce authentication bypass

CVE-2026-93928 · Severity: high · CVSS 7.3 · Published 2026-09-22

Technologies: MagePeople Taxi Booking Manager for WooCommerce. Vendors: MagePeople.

Executive brief

Taxi Booking Manager for WooCommerce is a WordPress plugin that manages ride-booking functionality for online stores. An authentication bypass vulnerability allows attackers to log in without valid credentials or impersonate other users, potentially gaining unauthorized access to booking data and administrative functions. This could lead to unauthorized bookings, data theft, or account takeover.

Technical details

The vulnerability is a broken authentication flaw in Taxi Booking Manager for WooCommerce versions before 2.0.8 that allows unauthenticated attackers to bypass login controls via an alternate path or channel. The attack requires no authentication or user interaction and can be exploited remotely. The vulnerability was patched in version 2.0.8.

Affected products

  • Magepeople Taxi Booking Manager for WooCommerce before 2.0.8

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Version 2.0.8 released

References

Related threats