WooCommerce Accommodation Bookings <= 1.3.12 - Unauthenticated Denial of Service via Availability Cache Registry
- ID
- WPSEC-2026-0649
- Plugin
- WooCommerce Accommodation Bookings (woocommerce-accommodation-bookings)
- Affected
- from 1.1.8 before 1.3.13
- Remediation
- Update to 1.3.13 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Weakness
- CWE-770
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
- Attack surface
- WooCommerce Accommodation Bookings on WPSec AttackSurface
- Fix released
- Published
Description
The WooCommerce Accommodation Bookings plugin for WordPress is vulnerable to uncontrolled resource consumption in versions 1.1.8 up to, and including, 1.3.12. This is due to the get_time_slots() function adding its cache key to the shared 'booking_slots_transient_keys' registry on every availability lookup, including lookups served from cache, with no deduplication or size limit, and rewriting the entire registry each time. This makes it possible for unauthenticated attackers to inflate the registry by repeatedly requesting availability for an accommodation product, increasing the database and memory cost of every later availability lookup and degrading site performance.
References
- https://wpsec.com/vuln/WPSEC-2026-0649/
- https://plugins.svn.wordpress.org/woocommerce-accommodation-bookings/tags/1.3.13/
- https://wordpress.org/plugins/woocommerce-accommodation-bookings/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS