PatchSiren cyber security CVE debrief
CVE-2026-25426 Magepeople inc. CVE debrief
A Missing Authorization vulnerability (CWE-862) in the Taxi Booking Manager for WooCommerce WordPress plugin allows exploitation of incorrectly configured access control security levels. The vulnerability affects versions from n/a through 2.0.1. The issue was published to the CVE List on 2026-05-26 and carries a CVSS 3.1 score of 5.3 (MEDIUM severity). The vulnerability is characterized by broken access control that could allow unauthorized actors to access functionality or data. No known exploitation in ransomware campaigns has been reported, and the vulnerability has not been added to CISA's Known Exploited Vulnerabilities (KEV) catalog.
- Vendor
- Magepeople inc.
- Product
- Taxi Booking Manager for WooCommerce
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-05-26
Who should care
WordPress site administrators using the Taxi Booking Manager for WooCommerce plugin; WooCommerce store operators; security teams managing WordPress plugin inventories; hosting providers offering WordPress managed services
Technical summary
The Taxi Booking Manager for WooCommerce plugin (versions through 2.0.1) contains a Missing Authorization vulnerability classified as CWE-862. The vulnerability stems from broken access control mechanisms that fail to properly validate user permissions before granting access to restricted functionality. With a CVSS 3.1 score of 5.3 (MEDIUM), the vulnerability has network attack vector, low attack complexity, requires no privileges, and no user interaction. The impact is limited to low confidentiality impact with no integrity or availability impact. The plugin vendor is Magepeople inc.
Defensive priority
medium
Recommended defensive actions
- Upgrade Taxi Booking Manager for WooCommerce plugin to a version newer than 2.0.1
- Review WordPress user role permissions and principle of least privilege
- Implement Web Application Firewall (WAF) rules to detect and block unauthorized access attempts to plugin endpoints
- Monitor access logs for anomalous requests to plugin administrative functions
- Conduct security assessment of other Magepeople inc. plugins for similar access control weaknesses
Evidence notes
Vulnerability identified by Patchstack and reported to CVE.org. NVD status is currently 'Deferred'. CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-25426 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-25426
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-25426 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-25426
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.