PT-2025-33540 · WordPress · Taxi Booking Manager For Woocommerce | E-Cab Plugin+1
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
E-cab plugin for WordPress versions prior to 1.3.1
Description:
The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account takeover. This is due to insufficient validation of a user's capabilities before updating plugin settings or user details, such as the email address. This allows unauthenticated attackers to modify arbitrary user email addresses, including those of administrators, and subsequently reset passwords to gain account access.
Recommendations:
Update the E-cab plugin to version 1.3.1 or later.
Correção
LPE
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
E-Cab Plugin
Taxi Booking Manager For Woocommerce | E-Cab Plugin