# Bus Ticket Booking with Seat Reservation <= 5.9.7 - Unauthenticated Price Manipulation via Ticket Type and Seat Selection

- **ID:** WPSEC-2026-0743
- **Plugin:** Bus Ticket Booking with Seat Reservation (`bus-ticket-booking-with-seat-reservation`), https://wordpress.org/plugins/bus-ticket-booking-with-seat-reservation/
- **Affected versions:** all versions before 5.9.8
- **Fixed in:** 5.9.8 (Update to 5.9.8 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-20
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/bus-ticket-booking-with-seat-reservation
- **Fix released:** 2026-10-09
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0743/

## Description

The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to price manipulation via the seat-plan booking and add-to-cart request in all versions up to, and including, 5.9.7. This is due to insufficient validation of the posted ticket (passenger) type and seat labels: a ticket type with no fare on the route was priced at 0 instead of being refused, and seats were never checked against the bus's seat plan. Cart recalculation at checkout had the same flaw. This makes it possible for unauthenticated attackers to book paid seats for free, or to add non-existent, non-seat or duplicate seats to the cart, in both the WooCommerce and Standalone checkout.

## References

- https://wpsec.com/vuln/WPSEC-2026-0743/
- https://plugins.svn.wordpress.org/bus-ticket-booking-with-seat-reservation/tags/5.9.8/
- https://wordpress.org/plugins/bus-ticket-booking-with-seat-reservation/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0743/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
