Access violation vulnerability in E-cab Taxi Booking Manager for Woocommerce 1.3.0

A plugin called “E-cab” for WordPress, which manages taxi bookings, has a security issue that could allow someone to gain more privileges than they should have. This can happen in all versions of the plugin, up to version 1.3.0. The problem is that the plugin doesn’t check a user’s permissions before letting them change a setting or their own information, like their email address. This means that someone who isn’t logged in could change an administrator’s email address, and then use that to reset their password and access their account.

Detected in:

E-cab Taxi Booking Manager for Woocommerce fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.