Vulnerabilities and security researches formwb-bookings-for-woocommerce mwb-bookings-for-woocommerce
Direction: ascendingJul 19, 2026
Bookings for WooCommerce – Schedule Appointments, Manage Bookings, Show Availability, Calendar Listings # CVE-2026-12393
- CVE, Research URL
- Date
- Jul 17, 2026
- Research Description
- The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing any authenticated user, such as a Subscriber or Customer, to cancel and void other customers' booking orders.
- Affected versions
-
max 3.11.7.
- Status
-
vulnerable