CVE-2026-84045

The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before pricing a booking, allowing unauthenticated attackers to manipulate the order total down to zero and place real taxi-booking orders at an arbitrary price.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 11:17

Updated : 2026-09-08 19:15


NVD link : CVE-2026-84045

Mitre link : CVE-2026-84045

CVE.ORG link : CVE-2026-84045


JSON object : View

Products Affected

No product.

CWE

No CWE.