CVE-2025-66105: WordPress Bus Ticket Booking with Seat Reservation plugin < 5.6.8 - Broken Access Control vulnerability
Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Bus Ticket Booking with Seat Reservation: from n/a before 5.6.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66105?
The severity of CVE-2025-66105 is classified as a broken access control vulnerability which can lead to unauthorized access.
How do I fix CVE-2025-66105?
To fix CVE-2025-66105, update the Bus Ticket Booking with Seat Reservation plugin to version 5.6.8 or higher.
What versions of the software are affected by CVE-2025-66105?
CVE-2025-66105 affects versions of the Bus Ticket Booking with Seat Reservation plugin prior to 5.6.8.
What kind of vulnerability is CVE-2025-66105?
CVE-2025-66105 is a broken access control vulnerability that results from missing authorization checks.
Who is the vendor of the affected product in CVE-2025-66105?
The vendor of the affected product in CVE-2025-66105 is Magepeople, responsible for the Bus Ticket Booking with Seat Reservation plugin.