GHSA-j5fj-p46h-2j27HighCVSS 7.5

The WooCommerce Bookings WordPress plugin before 3.11.0 does not limit a user-supplied value...

Published
October 11, 2026
Last Modified
October 11, 2026

🔗 CVE IDs covered (1)

📋 Description

The WooCommerce Bookings WordPress plugin before 3.11.0 does not limit a user-supplied value before using it to allocate memory in one of its unauthenticated AJAX actions, allowing unauthenticated attackers to exhaust server memory and cause a Denial of Service with a single request.

🔗 References (3)