ZeroHour

CVE-2026-48888

mass

Unauthenticated resource-exhaustion DoS in WooCommerce before 11.1.0

CVSS 3.1
7.5 high
EPSS
<1%p18
Published
()
Modified
AI analysis

WooCommerce, the e-commerce plugin for WordPress from Automattic, contains an 'Allocation of Resources Without Limits or Throttling' flaw (CWE-770) that allows HTTP denial of service. An unauthenticated remote attacker can trigger it over the network with low complexity by sending requests that cause the plugin to allocate resources without any cap or rate limiting, exhausting server capacity. The impact is availability-only: an attacker can degrade or take down the affected storefront but gains no confidentiality or integrity impact. Any WooCommerce deployment running a version before 11.1.0 is affected. Exploitation has not been observed: there is no known public proof-of-concept, the CVE is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Upgrade WooCommerce to version 11.1.0 or later, which resolves this issue. Until patched, check your installed WooCommerce version in the WordPress plugins list and consider WAF or reverse-proxy rate limiting on the store's public endpoints to blunt unauthenticated request floods. There is no evidence of active exploitation, so patching at normal priority is reasonable, though high-availability storefronts should patch sooner.

Affected
Automattic WooCommerceall versions before 11.1.0
Estimated exposure
mass≈5,000,000+ WordPress sites (WooCommerce active-install count on WordPress.org), most plausibly running pre-11.1.0 releases — WooCommerce is among the most-installed WordPress plugins with roughly 5 million active installations reported by the WordPress.org plugin directory, and typical update lag means a large share of those sites are likely still on versions…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.

Ecosystems
WordPress, E-commerce
Weakness
CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.