CVE-2026-14853

CVE-2026-14853: WooCommerce Bookings < 3.9.0 - Subscriber+ Draft Bookable Product Creation via Missing Authorization

Vendor Unknown
Product WooCommerce Bookings
Published August 23, 2026
Last update August 23, 2026

CVSS base score

What the vulnerability does

01Description

The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.

Key dates

02Disclosure timeline

August 23, 2026 CVE published