Authentication Bypass Vulnerability in Taxi Booking Manager for WooCommerce by Magepeople Inc.
CVE-2026-93928

7.3HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2026

What is CVE-2026-93928?

An authentication bypass vulnerability exists in the Taxi Booking Manager for WooCommerce by Magepeople Inc., affecting versions prior to 2.0.8. This flaw allows unauthorized users to gain access to restricted features without proper authentication. It exploits unvalidated alternate paths to bypass the security mechanisms of the plugin, potentially compromising user data and the integrity of the booking process. Website owners using this plugin are strongly advised to update to version 2.0.8 or later to address this security issue.

Affected Version(s)

Taxi Booking Manager for WooCommerce < 2.0.8

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thaer Assfour | Patchstack Bug Bounty Program
.