CyberRota Analysis
AI-GeneratedThe WooCommerce Bookings plugin for WordPress prior to version 3.9.0 is vulnerable due to inadequate capability checks on specific AJAX actions, allowing users with Subscriber-level access and higher to create draft bookable products without proper authorization. This flaw could lead to unauthorized product listings and potential misuse of the booking system. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.
Original NVD Description
The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.