
CVE-2026-14853 The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting… https://www.cve.org/CVERecord?id=CVE-2026-14853
Post summary
The entry discloses a capability-check bypass vulnerability in the WooCommerce Bookings WordPress plugin prior to version 3.9.0, with no mention of exploits, patches, or active exploitation.

