What the vulnerability does
01Description
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
What the vulnerability does
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
Explanation of Vulnerability in Simple Terms
The Taxi Booking Manager for WooCommerce plugin fails to properly check user permissions before allowing certain actions. An attacker without authentication can modify booking data or other protected information by sending direct requests to the plugin. This affects all versions up to 2.0.3. Site owners should update immediately when a patch becomes available.
What an attacker can do
Modify or create taxi bookings and related data without logging in.
Potential impact on your site
Booking data can be altered or created by unauthorized users, disrupting service and potentially causing financial loss.
Conditions required to exploit
None. The attacker needs only network access to your site.
Key dates
External resources
Related vulnerabilities