๐Ÿ” CVE Alert

CVE-2026-14853

UNKNOWN 0.0

WooCommerce Bookings < 3.9.0 - Subscriber+ Draft Bookable Product Creation via Missing Authorization

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.

Vendor unknown
Product woocommerce bookings
Published Aug 23, 2026
Stay Ahead of the Next One

Get instant alerts for unknown woocommerce bookings

Be the first to know when new unknown vulnerabilities affecting unknown woocommerce bookings are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WooCommerce Bookings
0 < 3.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/dd6ec707-3943-49be-81bb-c5dd51f2c001/

Credits

Mike Gozdiskowski WPScan