cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches formwb-bookings-for-woocommerce mwb-bookings-for-woocommerce

Direction: ascending
Jul 19, 2026

Bookings for WooCommerce – Schedule Appointments, Manage Bookings, Show Availability, Calendar Listings # CVE-2026-12393

CVE, Research URL

CVE-2026-12393

Date
Jul 17, 2026
Research Description
The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing any authenticated user, such as a Subscriber or Customer, to cancel and void other customers' booking orders.
Affected versions
max 3.11.7.
Status
vulnerable