WooCommerce Accommodation Bookings <= 1.3.12 - Unauthenticated Denial of Service via Availability Cache Registry

Medium 5.3 CWE-770Fixed in 1.3.13
ID
WPSEC-2026-0649
Plugin
WooCommerce Accommodation Bookings (woocommerce-accommodation-bookings)
Affected
from 1.1.8 before 1.3.13
Remediation
Update to 1.3.13 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness
CWE-770
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
WooCommerce Accommodation Bookings on WPSec AttackSurface
Fix released
Published

Description

The WooCommerce Accommodation Bookings plugin for WordPress is vulnerable to uncontrolled resource consumption in versions 1.1.8 up to, and including, 1.3.12. This is due to the get_time_slots() function adding its cache key to the shared 'booking_slots_transient_keys' registry on every availability lookup, including lookups served from cache, with no deduplication or size limit, and rewriting the entire registry each time. This makes it possible for unauthenticated attackers to inflate the registry by repeatedly requesting availability for an accommodation product, increasing the database and memory cost of every later availability lookup and degrading site performance.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0