CVE-2026-14853

The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-23 06:17

Updated : 2026-08-26 16:30


NVD link : CVE-2026-14853

Mitre link : CVE-2026-14853

CVE.ORG link : CVE-2026-14853


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization