Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking Manager for WooCommerce: from n/a before 2.0.8.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-93928 represents a critical authentication bypass vulnerability in the Magepeople Taxi Booking Manager plugin for WooCommerce, affecting versions before 2.0.8. This CWE-288 vulnerability allows attackers to circumvent standard authentication mechanisms through alternate paths or channels, potentially gaining unauthorized access to booking systems, customer data, and administrative functions. Organizations running WooCommerce installations with this plugin are at direct risk, particularly taxi services, ride-sharing platforms, and any business leveraging this booking solution for customer transactions and sensitive information management.
While this CVE maps to CWE-288 rather than specific MITRE ATT&CK techniques, Casky's platform would help practitioners identify suspicious authentication patterns through behavioral analysis. Although no direct MITRE technique mapping exists for this vulnerability, security teams using Casky could detect exploitation attempts by monitoring for unusual authentication flows, session manipulation, or access to administrative functions bypassing normal credential validation. Practitioners would see findings related to initial access and privilege escalation attempts, enabling them to correlate logs showing authentication requests using alternate channels, unexpected API calls, or direct database access patterns that circumvent the WooCommerce authentication layer.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-93928. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation