CVE-2026-73363: WordPress Taxi Booking Manager for WooCommerce plugin < 2.0.8 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Taxi Booking Manager for WooCommerce Pluginto a version that resolves this vulnerability.Fixed in 2.0.8
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerability is described as unauthenticated, so an attacker does not need a WordPress account or prior authentication to exploit it.
What is the likely security impact?
The supplied CVSS vector indicates high integrity impact, with no stated confidentiality or availability impact. Successful exploitation could allow unauthorized modification of affected data or actions.
Which installations are affected?
Taxi Booking Manager for WooCommerce versions earlier than 2.0.8 are affected. Updating to version 2.0.8 or later removes the affected version range.