CVE-2026-14854 PUBLISHED

WooCommerce Bookings < 3.11.0 - Unauthenticated Denial of Service

Assigner: WPScan
Reserved: 06.07.2026 Published: 11.10.2026 Updated: 11.10.2026

The WooCommerce Bookings WordPress plugin before 3.11.0 does not limit a user-supplied value before using it to allocate memory in one of its unauthenticated AJAX actions, allowing unauthenticated attackers to exhaust server memory and cause a Denial of Service with a single request.

Product Status

Vendor Unknown
Product WooCommerce Bookings
Versions Default: unaffected
  • affected from 0 to 3.11.0 (excl.)

Credits

  • Mike Gozdiskowski finder
  • WPScan coordinator

References

Problem Types

  • CWE-400 Uncontrolled Resource Consumption CWE