Chauffeur Taxi Booking System for WordPress <= 6.9 - Authentication Bypass

2024-05-19 00:00
Kursat Cetin

Strategic Overview

Status
Patched in 7.0
Affected Version<= 6.9
CVSS9.1Critical
CVECVE-2024-32692
View all Chauffeur Taxi Booking System for WordPress vulnerabilities

Vulnerability Overview

The Chauffeur Taxi Booking System for WordPress plugin for WordPress is vulnerable to authenticated bypass in all versions up to, and including, 6.9. This is due to the plugin not properly validating a user's identity. This makes it possible for unauthenticated attackers to perform unauthorized actions.

Technical Analysis

REMEDIATION: Update to version 7.0, or a newer patched version --- IDENTIFIER: CWE-287 (Improper Authentication) When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C