{
 "id": "WPSEC-2026-0743",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0743/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0743/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0743/index.md",
 "title": "Bus Ticket Booking with Seat Reservation <= 5.9.7 - Unauthenticated Price Manipulation via Ticket Type and Seat Selection",
 "description": "The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to price manipulation via the seat-plan booking and add-to-cart request in all versions up to, and including, 5.9.7. This is due to insufficient validation of the posted ticket (passenger) type and seat labels: a ticket type with no fare on the route was priced at 0 instead of being refused, and seats were never checked against the bus's seat plan. Cart recalculation at checkout had the same flaw. This makes it possible for unauthenticated attackers to book paid seats for free, or to add non-existent, non-seat or duplicate seats to the cart, in both the WooCommerce and Standalone checkout.",
 "plugin": {
  "slug": "bus-ticket-booking-with-seat-reservation",
  "name": "Bus Ticket Booking with Seat Reservation",
  "full_name": "Bus Ticket Booking with Seat Reservation",
  "wordpress_org": "https://wordpress.org/plugins/bus-ticket-booking-with-seat-reservation/",
  "advisories_url": "https://wpsec.com/vuln/plugin/bus-ticket-booking-with-seat-reservation/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/bus-ticket-booking-with-seat-reservation"
 },
 "type": "BYPASS",
 "cwe": [
  "CWE-20"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "5.9.8",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 5.9.8"
  ]
 },
 "introduced_in": null,
 "fixed_in": "5.9.8",
 "remediation": "Update to 5.9.8 or later.",
 "fix_released": "2026-10-09T06:37:39+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:54:01.204879+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0743/",
  "https://plugins.svn.wordpress.org/bus-ticket-booking-with-seat-reservation/tags/5.9.8/",
  "https://wordpress.org/plugins/bus-ticket-booking-with-seat-reservation/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/bus-ticket-booking-with-seat-reservation",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-10"
 }
}