Sceawere
Vulnerability Detail
CVE-2026-14854UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Memory Exhaustion DoS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- WooCommerce Bookings
- Attack Type
- CWE-400 Uncontrolled Resource Consumption
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The WooCommerce Bookings WordPress plugin before 3.11.0 does not limit a user-supplied value before using it to allocate memory in one of its unauthenticated AJAX actions, allowing unauthenticated attackers to exhaust server memory and cause a Denial of Service with a single request.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-11T07:17:24.003Z",
"pubdate": "2026-10-11T07:17:24.003Z",
"executiveSummary": "The WooCommerce Bookings plugin for WordPress contains an unauthenticated memory exhaustion vulnerability affecting versions prior to 3.11.0.\nThis flaw allows remote, unauthenticated attackers to trigger a Denial of Service (DoS) condition by sending a single, maliciously crafted request to an AJAX action.\nThe vulnerability stems from improper validation of user-supplied input used during memory allocation procedures.\nBy manipulating specific parameters, an attacker can force the server to allocate excessive amounts of memory, leading to resource depletion and service instability.\nThe risk is critical as the attack requires no authentication or special privileges, making it accessible to any external threat actor with network reach to the WordPress instance.\nSuccessful exploitation results in the inability of the server to process further requests, effectively taking the targeted service offline.",
"technicalDetails": "The vulnerability is identified as a lack of input validation and boundary checking within an unauthenticated AJAX action provided by the WooCommerce Bookings plugin.\nThe root cause of this memory exhaustion flaw is the application's failure to sanitize or validate a specific user-supplied value before passing it into a memory allocation function.\nIn the context of the affected AJAX endpoint, the plugin logic accepts an attacker-controlled variable intended for internal data processing. Because the application logic does not impose strict constraints or maximum thresholds on this value, it allows for the request of disproportionately large memory buffers.\nThe attack flow begins when an unauthenticated attacker identifies the vulnerable AJAX action. The attacker then constructs an HTTP request (typically via GET or POST) containing a payload that specifies an abnormally large size or quantity value in the vulnerable parameter.\nUpon receiving this request, the server-side script invokes the affected function. Because the input remains unvalidated, the PHP engine proceeds to request memory allocation from the system based on the attacker's supplied value.\nThis behavior rapidly consumes available RAM allocated to the PHP process. When a single request is sufficient to saturate the available memory pool, the server triggers an out-of-memory (OOM) error, potentially leading to a crash of the web server process (e.g., PHP-FPM or Apache).\nThis vulnerability is particularly severe due to its unauthenticated nature and the fact that it can be triggered with a single, highly efficient request, requiring minimal bandwidth or complex infrastructure from the attacker.\nThe scope of impact is limited to the targeted WordPress instance's availability; however, in shared hosting environments, this could potentially degrade performance for other sites hosted on the same server depending on the resource isolation configuration.\nThe vulnerability affects all versions of the WooCommerce Bookings plugin prior to 3.11.0."
}