CVE-2026-14854: WooCommerce Bookings < 3.11.0 - Unauthenticated Denial of Service
Published Oct 11, 2026
·Updated
The WooCommerce Bookings WordPress plugin before 3.11.0 does not limit a user-supplied value before using it to allocate memory in one of its unauthenticated AJAX actions, allowing unauthenticated attackers to exhaust server memory and cause a Denial of Service with a single request.
Affected Software
1 affected component
WooCommerce WooCommerce Bookings<3.11.0
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness