Executive brief
Taxi Booking Manager for WooCommerce is a WordPress plugin that manages ride-booking functionality for online stores. An authentication bypass vulnerability allows attackers to log in without valid credentials or impersonate other users, potentially gaining unauthorized access to booking data and administrative functions. This could lead to unauthorized bookings, data theft, or account takeover.
Technical details
The vulnerability is a broken authentication flaw in Taxi Booking Manager for WooCommerce versions before 2.0.8 that allows unauthenticated attackers to bypass login controls via an alternate path or channel. The attack requires no authentication or user interaction and can be exploited remotely. The vulnerability was patched in version 2.0.8.
Affected products
- Magepeople Taxi Booking Manager for WooCommerce before 2.0.8
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Version 2.0.8 released