๐Ÿ” CVE Alert

CVE-2026-14854

UNKNOWN 0.0

WooCommerce Bookings < 3.11.0 - Unauthenticated Denial of Service

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The WooCommerce Bookings WordPress plugin before 3.11.0 does not limit a user-supplied value before using it to allocate memory in one of its unauthenticated AJAX actions, allowing unauthenticated attackers to exhaust server memory and cause a Denial of Service with a single request.

Vendor unknown
Product woocommerce bookings
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown woocommerce bookings

Be the first to know when new unknown vulnerabilities affecting unknown woocommerce bookings are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WooCommerce Bookings
0 < 3.11.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/7b6aeaed-7600-4cf9-ba43-8a6fefb1a244/

Credits

Mike Gozdiskowski WPScan