SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-14853

MEDIUM · CVSS 4.3 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-23 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The WooCommerce Bookings plugin for WordPress prior to version 3.9.0 is vulnerable due to inadequate capability checks on specific AJAX actions, allowing users with Subscriber-level access and higher to create draft bookable products without proper authorization. This flaw could lead to unauthorized product listings and potential misuse of the booking system. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-14853
Severity
MEDIUM
CVSS
4.3
EPSS
0.17%
WordPress

Original NVD Description

The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.