plugin

Ecab Taxi Booking Manager Vulnerabilities

14 known security issues reported for the Ecab Taxi Booking Manager WordPress plugin. Most recent disclosed Aug 19, 2026.

1 critical 1 high 7 medium

Running Ecab Taxi Booking Manager on your site? Check whether your installed version is affected.

Scan your site free

E-cab Taxi Booking Manager for Woocommerce < 2.0.8 - Missing Authorization

medium

The E-cab Taxi Booking Manager for Woocommerce plugin for WordPress is vulnerable to unauthorized access in all versions up to 2.0.8. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.0.8
Fixed in:
2.0.8
Disclosed:
Aug 19, 2026

CVE-2026-73363 on NVD →

E-cab Taxi Booking Manager for Woocommerce <= 2.0.3 - Missing Authorization

medium

The E-cab Taxi Booking Manager for Woocommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.0.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.0.3
Fixed in:
2.0.5
Disclosed:
Aug 10, 2026

CVE-2026-27345 on NVD →

E-cab Taxi Booking Manager for Woocommerce <= 2.0.1 - Missing Authorization

medium

The E-cab Taxi Booking Manager for Woocommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.0.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.0.1
Fixed in:
2.0.2
Disclosed:
May 26, 2026

CVE-2026-25426 on NVD →

E-cab Taxi Booking Manager for Woocommerce <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The E-cab Taxi Booking Manager for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbi...

CVSS:
6.4
Affected:
up to 2.0.0
Fixed in:
2.0.1
Disclosed:
Apr 23, 2026

CVE-2026-28040 on NVD →

Taxi Booking Manager for WooCommerce <= 1.3.0 - Missing Authorization

medium

The E-cab Taxi Booking Manager for Woocommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.3.0
Fixed in:
1.3.1
Disclosed:
Aug 25, 2025

CVE-2025-54713 on NVD →

E-cab Taxi Booking Manager for Woocommerce [ecab-taxi-booking-manager] <= 1.3.0 (unfixed)

unknown

[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce allows Authentication Abuse. This issue affects Taxi Booking Manager for WooCommerce: from n/a through 1.3.0.

Affected:
up to 1.3.0
Fix:
No patched version reported
Disclosed:
Aug 20, 2025

CVE-2025-54713 on NVD →

Taxi Booking Manager for Woocommerce | E-cab <= 1.3.0 - Missing Authorization to Unauthenticated Privilege Escalation via Account Takeover

critical

The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.0. This is due to the plugin not properly validating a user's capabilities prior to updating a plugin setting or their identity prior to updating the...

CVSS:
9.8
Affected:
up to 1.3.0
Fixed in:
1.3.1
Disclosed:
Aug 15, 2025

CVE-2025-8898 on NVD →

Taxi Booking Manager for WooCommerce <= 1.2.1 - Missing Authorization

medium

The Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.2.1
Fixed in:
1.2.2
Disclosed:
Mar 27, 2025

CVE-2025-30839 on NVD →

E-cab Taxi Booking Manager for Woocommerce [ecab-taxi-booking-manager] < 1.2.2 (closed)

unknown

[en] Missing Authorization vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxi Booking Manager for WooCommerce: from n/a through 1.2.1.

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Mar 27, 2025

CVE-2025-30839 on NVD →

E-cab Taxi Booking Manager for Woocommerce [ecab-taxi-booking-manager] < 1.1.9 (closed)

unknown

[en] Deserialization of Untrusted Data vulnerability in MagePeople Team Taxi Booking Manager for WooCommerce allows Object Injection.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 1.1.8.

Affected:
up to 1.1.9
Fixed in:
1.1.9
Disclosed:
Feb 3, 2025

CVE-2025-24661 on NVD →

Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab <= 1.1.8 - Authenticated (Contributor+) PHP Object Injection

high

The Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.8 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP O...

CVSS:
8.8
Affected:
up to 1.1.8
Fixed in:
1.1.9
Disclosed:
Jan 20, 2025

CVE-2025-24661 on NVD →

Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab <= 1.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with adminis...

CVSS:
4
Affected:
up to 1.0.9
Fixed in:
1.1.0
Disclosed:
Aug 29, 2024

CVE-2024-43986 on NVD →

E-cab Taxi Booking Manager for Woocommerce [ecab-taxi-booking-manager] < 1.1.0 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople Team Taxi Booking Manager for WooCommerce allows Stored XSS.This issue affects Taxi Booking Manager for WooCommerce: through 1.0.9.

Affected:
up to 1.1.0
Fixed in:
1.1.0
Disclosed:
Aug 29, 2024

CVE-2024-43986 on NVD →

E-cab Taxi Booking Manager for Woocommerce [ecab-taxi-booking-manager] < 1.3.1 (closed)

unknown
Affected:
up to 1.3.1
Fixed in:
1.3.1

CVE-2025-8898 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database