← back
CVE-2026-14853mediumCWE-862

WooCommerce Bookings < 3.9.0 - Subscriber+ Draft Bookable Product Creation via Missing Authorization

10Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.3
exploitation probability
observed exploitation
nono source reports it
The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N