Security Advisory

CVE-2026-14853

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-23 06:00:17
Last updated 2026-08-23 15:33:37
Assigner WPScan
CVSS score 4.3
State PUBLISHED

Description

The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.