The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.
CVE-2026-14853
NONE
EPSS 0.19%
Updated Aug 23, 2026
WordPress
unknown:woocommerce bookings
CVE Details
CVE ID
CVE-2026-14853
Published Date
Aug 23, 2026
Vendor
WordPress
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.19%
Likelihood of exploitation in next 30 days
Percentile:
9.1th percentile (higher than 9.1% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory