SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84045

MEDIUM · CVSS 5.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The E-cab Taxi Booking Manager for WooCommerce plugin in WordPress versions prior to 2.0.5 is vulnerable due to insufficient validation of client-supplied trip distance and base-price values, enabling unauthenticated attackers to set the order total to zero and submit fraudulent taxi bookings. This vulnerability poses a risk of financial loss and service abuse for businesses using the plugin. WordPress site administrators utilizing this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-84045
Severity
MEDIUM
CVSS
5.3
EPSS
0.19%
WordPress

Original NVD Description

The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before pricing a booking, allowing unauthenticated attackers to manipulate the order total down to zero and place real taxi-booking orders at an arbitrary price.