Feed/CVE-2026-14853
CVE-2026-14853MEDIUMCVSS 4.3

CVE-2026-14853

Published Aug 23, 2026·Updated Aug 23, 2026

NVD Description

The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free