Executive brief
WooCommerce Bookings is a popular WordPress plugin that allows site owners to create and manage bookable products and services. A flaw in the plugin allows low-privilege users (Subscribers) to create draft bookable products by bypassing authorization checks on an AJAX action, potentially leading to unauthorized content creation and manipulation of the product catalog.
Technical details
The vulnerability is a broken access control issue (CWE-862) affecting an AJAX action in WooCommerce Bookings. The plugin fails to perform capability checks on the wc_bookings_get_product_template AJAX handler, and its nonce check can be bypassed by simply omitting the security token parameter. An attacker with Subscriber-level access or higher can POST directly to admin-ajax.php without authentication restrictions to create draft bookable products with arbitrary index and slug parameters. The vulnerability allows unauthorized product creation accessible only to administrator accounts, exposing the product management interface to privilege escalation. A patch is available in version 3.9.0.
Affected products
- Automattic WooCommerce Bookings before 3.9.0
Timeline
- 2026-08-21: disclosed
- 2026-08-23: patched: Fix released in version 3.9.0