Bus Ticket Booking with Seat Reservation <= 5.9.7 - Unauthenticated Price Manipulation via Ticket Type and Seat Selection

Medium 5.3 CWE-20Fixed in 5.9.8
ID
WPSEC-2026-0743
Plugin
Bus Ticket Booking with Seat Reservation (bus-ticket-booking-with-seat-reservation)
Affected
all versions before 5.9.8
Remediation
Update to 5.9.8 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-20
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-10
Attack surface
Bus Ticket Booking with Seat Reservation on WPSec AttackSurface
Fix released
Published

Description

The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to price manipulation via the seat-plan booking and add-to-cart request in all versions up to, and including, 5.9.7. This is due to insufficient validation of the posted ticket (passenger) type and seat labels: a ticket type with no fare on the route was priced at 0 instead of being refused, and seats were never checked against the bus's seat plan. Cart recalculation at checkout had the same flaw. This makes it possible for unauthenticated attackers to book paid seats for free, or to add non-existent, non-seat or duplicate seats to the cart, in both the WooCommerce and Standalone checkout.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0