Impact
The affected WooCommerce Bookings plugin does not perform a capability check for an AJAX action that creates new bookable products, and its nonce check can be bypassed by omitting the token. A user with a Subscriber role or higher can therefore trigger this action and create draft bookable products. This flaw allows an attacker to introduce malicious or spam bookable items without supervision, potentially disrupting the e‑commerce experience, violating business rules, or enabling further attacks if the products contain harmful links or code.
Affected Systems
All WordPress sites running WooCommerce Bookings versions earlier than 3.9.0 are vulnerable. Any user who can authenticate as a Subscriber or higher has the ability to exploit the missing authorization check.
Risk and Exploitability
Because the exploitation requires only a normal authenticated web user with Subscriber‑level or higher privileges, the attack vector is straightforward and does not require special access or technical knowledge beyond logging into the site. The EPSS score of < 1% and the fact that it is not listed in CISA KEV suggest a low exploitation probability, yet the CVSS score of 4.3 indicates a moderate impact for the site. The ability to create draft products without supervision can affect platform integrity and business operations. A simple web request to the vulnerable endpoint is sufficient to trigger the unauthorized content.
OpenCVE Enrichment