WordPress Plugin Vulnerabilities

WooCommerce Bookings < 3.11.0 - Unauthenticated Denial of Service

Description

The plugin does not limit a user-supplied value before using it to allocate memory in one of its unauthenticated AJAX actions, allowing unauthenticated attackers to exhaust server memory and cause a Denial of Service with a single request.

Proof of Concept

Affects Plugins

Fixed in 3.11.0

References

Miscellaneous

Original Researcher
Mike Gozdiskowski
Submitter
Mike Gozdiskowski
Verified
Yes

Timeline

Publicly Published
2026-10-09 (about 2 days ago)
Added
2026-10-09 (about 1 day ago)
Last Updated
2026-10-09 (about 1 day ago)

Other