Missing Authorization in Taxi Booking Manager for WooCommerce by Magepeople Inc.
CVE-2026-25426
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 May 2026
What is CVE-2026-25426?
A missing authorization vulnerability has been identified in the Taxi Booking Manager for WooCommerce by Magepeople Inc. This flaw allows unauthorized access due to incorrectly configured access control security levels. As a result, attackers may exploit this weakness to gain unauthorized actions on the system, posing significant risks to data integrity and user privacy. All versions from n/a through 2.0.1 are affected, making it critical for users to review their security settings and implement any necessary updates or patches.
Affected Version(s)
Taxi Booking Manager for WooCommerce <= 2.0.1