Bus Ticket Booking with Seat Reservation <= 5.9.7 - Unauthenticated Price Manipulation via Ticket Type and Seat Selection
- ID
- WPSEC-2026-0743
- Plugin
- Bus Ticket Booking with Seat Reservation (bus-ticket-booking-with-seat-reservation)
- Affected
- all versions before 5.9.8
- Remediation
- Update to 5.9.8 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-20
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-10
- Attack surface
- Bus Ticket Booking with Seat Reservation on WPSec AttackSurface
- Fix released
- Published
Description
The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to price manipulation via the seat-plan booking and add-to-cart request in all versions up to, and including, 5.9.7. This is due to insufficient validation of the posted ticket (passenger) type and seat labels: a ticket type with no fare on the route was priced at 0 instead of being refused, and seats were never checked against the bus's seat plan. Cart recalculation at checkout had the same flaw. This makes it possible for unauthenticated attackers to book paid seats for free, or to add non-existent, non-seat or duplicate seats to the cart, in both the WooCommerce and Standalone checkout.
References
- https://wpsec.com/vuln/WPSEC-2026-0743/
- https://plugins.svn.wordpress.org/bus-ticket-booking-with-seat-reservation/tags/5.9.8/
- https://wordpress.org/plugins/bus-ticket-booking-with-seat-reservation/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS