CVE-2026-48888
massUnauthenticated resource-exhaustion DoS in WooCommerce before 11.1.0
WooCommerce, the e-commerce plugin for WordPress from Automattic, contains an 'Allocation of Resources Without Limits or Throttling' flaw (CWE-770) that allows HTTP denial of service. An unauthenticated remote attacker can trigger it over the network with low complexity by sending requests that cause the plugin to allocate resources without any cap or rate limiting, exhausting server capacity. The impact is availability-only: an attacker can degrade or take down the affected storefront but gains no confidentiality or integrity impact. Any WooCommerce deployment running a version before 11.1.0 is affected. Exploitation has not been observed: there is no known public proof-of-concept, the CVE is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Upgrade WooCommerce to version 11.1.0 or later, which resolves this issue. Until patched, check your installed WooCommerce version in the WordPress plugins list and consider WAF or reverse-proxy rate limiting on the store's public endpoints to blunt unauthenticated request floods. There is no evidence of active exploitation, so patching at normal priority is reasonable, though high-availability storefronts should patch sooner.
| Automattic WooCommerce | all versions before 11.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.
- Ecosystems
- WordPress, E-commerce
- Weakness
- CWE-770
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.