CVE-2026-14853: WooCommerce Bookings < 3.9.0 - Subscriber+ Draft Bookable Product Creation via Missing Authorization
Published Aug 23, 2026
·Updated
The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.
Affected Software
1 affected component
WooCommerce WooCommerce Bookings WordPress plugin<3.9.0
Event History
Aug 23, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
Description
Frequently Asked Questions
1
Which users can exploit this issue?
Any authenticated user with Subscriber-level access or higher can exploit the affected AJAX action. The issue does not require administrative or product-management capabilities.
2
Does exploitation require a valid AJAX nonce?
No. The nonce check can be bypassed by omitting the token from the request.
3
What is the impact of successful exploitation?
An attacker can create draft bookable products. The provided information does not indicate that they can publish those products or modify existing ones.
4
What versions are affected?
WooCommerce Bookings versions before 3.9.0 are affected.