CVE-2023-32747 MEDIUM

CVE-2023-32747: WordPress WooCommerce Bookings Plugin <= 1.15.78 is vulnerable to Insecure Direct Object References (IDOR)

Vendor Woocommerce
Product WooCommerce Bookings
Weakness CWE-639 · IDOR
Published December 21, 2023
Last update April 28, 2026

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 1.15.78.

Explanation of Vulnerability in Simple Terms

02Summary

WooCommerce Bookings versions up to 1.15.78 contain an authorization flaw that allows authenticated users with low privileges to modify booking data and disrupt service availability. The vulnerability does not expose sensitive information but can corrupt booking records or prevent legitimate bookings from being processed. Site owners should update to a version newer than 1.15.78.

What an attacker can do

03Attacker Capabilities

Modify booking records or cause booking system disruption with a low-privilege account.

Potential impact on your site

04Site Impact

Booking data integrity compromised; legitimate bookings may fail or be altered by unauthorized users.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege authenticated account on the site.

Key dates

06Disclosure timeline

December 21, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE