# WooCommerce Accommodation Bookings <= 1.3.12 - Unauthenticated Denial of Service via Availability Cache Registry

- **ID:** WPSEC-2026-0649
- **Plugin:** WooCommerce Accommodation Bookings (`woocommerce-accommodation-bookings`), https://wordpress.org/plugins/woocommerce-accommodation-bookings/
- **Affected versions:** from 1.1.8 before 1.3.13
- **Fixed in:** 1.3.13 (Update to 1.3.13 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
- **Weakness:** CWE-770
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/woocommerce-accommodation-bookings
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0649/

## Description

The WooCommerce Accommodation Bookings plugin for WordPress is vulnerable to uncontrolled resource consumption in versions 1.1.8 up to, and including, 1.3.12. This is due to the get_time_slots() function adding its cache key to the shared 'booking_slots_transient_keys' registry on every availability lookup, including lookups served from cache, with no deduplication or size limit, and rewriting the entire registry each time. This makes it possible for unauthenticated attackers to inflate the registry by repeatedly requesting availability for an accommodation product, increasing the database and memory cost of every later availability lookup and degrading site performance.

## References

- https://wpsec.com/vuln/WPSEC-2026-0649/
- https://plugins.svn.wordpress.org/woocommerce-accommodation-bookings/tags/1.3.13/
- https://wordpress.org/plugins/woocommerce-accommodation-bookings/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0649/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
