E-cab Taxi Booking Manager for Woocommerce < 2.0.8 - Missing Authorization
medium
The E-cab Taxi Booking Manager for Woocommerce plugin for WordPress is vulnerable to unauthorized access in all versions up to 2.0.8. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.8
- Disclosed:
- Aug 19, 2026
CVE-2026-73363 on NVD →
E-cab Taxi Booking Manager for Woocommerce <= 2.0.3 - Missing Authorization
medium
The E-cab Taxi Booking Manager for Woocommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.0.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.5
- Disclosed:
- Aug 10, 2026
CVE-2026-27345 on NVD →
E-cab Taxi Booking Manager for Woocommerce <= 2.0.1 - Missing Authorization
medium
The E-cab Taxi Booking Manager for Woocommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.0.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- May 26, 2026
CVE-2026-25426 on NVD →
E-cab Taxi Booking Manager for Woocommerce <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The E-cab Taxi Booking Manager for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbi...
- CVSS:
- 6.4
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.1
- Disclosed:
- Apr 23, 2026
CVE-2026-28040 on NVD →
Taxi Booking Manager for WooCommerce <= 1.3.0 - Missing Authorization
medium
The E-cab Taxi Booking Manager for Woocommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.1
- Disclosed:
- Aug 25, 2025
CVE-2025-54713 on NVD →
E-cab Taxi Booking Manager for Woocommerce [ecab-taxi-booking-manager] <= 1.3.0 (unfixed)
unknown
[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce allows Authentication Abuse. This issue affects Taxi Booking Manager for WooCommerce: from n/a through 1.3.0.
- Affected:
- up to 1.3.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 20, 2025
CVE-2025-54713 on NVD →
Taxi Booking Manager for Woocommerce | E-cab <= 1.3.0 - Missing Authorization to Unauthenticated Privilege Escalation via Account Takeover
critical
The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.0. This is due to the plugin not properly validating a user's capabilities prior to updating a plugin setting or their identity prior to updating the...
- CVSS:
- 9.8
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.1
- Disclosed:
- Aug 15, 2025
CVE-2025-8898 on NVD →
Taxi Booking Manager for WooCommerce <= 1.2.1 - Missing Authorization
medium
The Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.2
- Disclosed:
- Mar 27, 2025
CVE-2025-30839 on NVD →
E-cab Taxi Booking Manager for Woocommerce [ecab-taxi-booking-manager] < 1.2.2 (closed)
unknown
[en] Missing Authorization vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxi Booking Manager for WooCommerce: from n/a through 1.2.1.
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Mar 27, 2025
CVE-2025-30839 on NVD →
E-cab Taxi Booking Manager for Woocommerce [ecab-taxi-booking-manager] < 1.1.9 (closed)
unknown
[en] Deserialization of Untrusted Data vulnerability in MagePeople Team Taxi Booking Manager for WooCommerce allows Object Injection.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 1.1.8.
- Affected:
- up to 1.1.9
- Fixed in:
- 1.1.9
- Disclosed:
- Feb 3, 2025
CVE-2025-24661 on NVD →
Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab <= 1.1.8 - Authenticated (Contributor+) PHP Object Injection
high
The Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.8 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP O...
- CVSS:
- 8.8
- Affected:
- up to 1.1.8
- Fixed in:
- 1.1.9
- Disclosed:
- Jan 20, 2025
CVE-2025-24661 on NVD →
Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab <= 1.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with adminis...
- CVSS:
- 4
- Affected:
- up to 1.0.9
- Fixed in:
- 1.1.0
- Disclosed:
- Aug 29, 2024
CVE-2024-43986 on NVD →
E-cab Taxi Booking Manager for Woocommerce [ecab-taxi-booking-manager] < 1.1.0 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople Team Taxi Booking Manager for WooCommerce allows Stored XSS.This issue affects Taxi Booking Manager for WooCommerce: through 1.0.9.
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.0
- Disclosed:
- Aug 29, 2024
CVE-2024-43986 on NVD →
E-cab Taxi Booking Manager for Woocommerce [ecab-taxi-booking-manager] < 1.3.1 (closed)
unknown
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
CVE-2025-8898 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database