PT-2026-79760 · WordPress · Woocommerce Bookings

·

CVE-2026-14853

·

Published

2026-08-23

·

Updated

2026-08-23

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WooCommerce Bookings versions prior to 3.9.0
Description An issue exists where a capability check is not performed on an AJAX action. Additionally, the nonce check—a security measure used to prevent cross-site request forgery—can be bypassed by omitting the token. This allows users with Subscriber-level access and above to create draft bookable products.
Recommendations Update WooCommerce Bookings to version 3.9.0 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14853

Affected Products

Woocommerce Bookings