PT-2025-33540 · WordPress · Taxi Booking Manager For Woocommerce | E-Cab Plugin+1
Phat Rio
·
Published
2025-08-16
·
Updated
2025-08-21
·
CVE-2025-8898
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
E-cab plugin for WordPress versions prior to 1.3.1
Description:
The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account takeover. This is due to insufficient validation of a user's capabilities before updating plugin settings or user details, such as the email address. This allows unauthenticated attackers to modify arbitrary user email addresses, including those of administrators, and subsequently reset passwords to gain account access.
Recommendations:
Update the E-cab plugin to version 1.3.1 or later.
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
E-Cab Plugin
Taxi Booking Manager For Woocommerce | E-Cab Plugin