CVE-2026-25426: WordPress Taxi Booking Manager for WooCommerce plugin <= 2.0.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Taxi Booking Manager for WooCommerce Pluginto a version that resolves this vulnerability.Fixed in 2.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25426?
CVE-2026-25426 has a medium severity rating of 5.3.
How do I fix CVE-2026-25426?
To fix CVE-2026-25426, update the WordPress Taxi Booking Manager for WooCommerce plugin to version 2.0.2 or later.
What type of vulnerability is CVE-2026-25426?
CVE-2026-25426 is classified as a Broken Access Control vulnerability.
What plugin is affected by CVE-2026-25426?
CVE-2026-25426 affects the MagePeople Taxi Booking Manager for WooCommerce plugin.
What versions of the plugin are vulnerable to CVE-2026-25426?
Versions of the Taxi Booking Manager for WooCommerce plugin up to and including 2.0.1 are vulnerable to CVE-2026-25426.