Update WooCommerce Bookings to the current 3.9.0 release through your normal licensed extension-maintenance workflow. NVD lists CVE-2026-14853 in releases before 3.9.0. For a booking store, treat this as a prompt maintenance task: update the extension, review staff access, and check that normal booking administration and customer-facing availability still work as expected.
This guidance is for store owners, agencies, and hosting teams that use WooCommerce Bookings. It focuses on a safe update and verification path without publishing technical attack details.
Who Should Update
- Stores running WooCommerce Bookings before 3.9.0.
- Stores where staff, contractors, or other non-administrator accounts can sign in.
- Agencies and managed hosts that maintain booking stores for more than one customer.
Update WooCommerce Bookings Safely
- Confirm the installed WooCommerce Bookings version in the WordPress Plugins screen or through the approved WooCommerce extension workflow.
- Review the store's normal maintenance window, recovery plan, and owner contact before changing a live booking workflow. Do not create or alter a backup schedule solely for this update.
- Update WooCommerce Bookings to 3.9.0 through the normal licensed update path.
- Keep WordPress core, WooCommerce, the active theme, and related booking extensions current as part of routine maintenance.
Review Staff Access After Updating
- Confirm that WooCommerce Bookings now reports version 3.9.0.
- Review WordPress users and remove accounts that no longer need store access.
- Ensure each active account has only the role and permissions needed for normal work.
- Review ordinary WordPress and WooCommerce error telemetry for unexpected booking-product changes, then handle validated findings through the established support process.
Verify the Booking Flow
- Check an existing booking product and its availability calendar.
- Make a controlled test booking only when the store's normal maintenance process permits it.
- Confirm that the customer confirmation and staff notification follow the store's expected process.
- Check the customer account view and the booking-management screen for clear, expected results.
If You Cannot Update Immediately
Limit booking-management access to approved staff, review lower-privilege accounts, and schedule supported maintenance as soon as practical. Temporary access restrictions are not a substitute for the current release.
Related FixItPhill Guidance
- How to check WooCommerce orders after maintenance
- How to test a WordPress staging site before launch
- FixItPhill WordPress support hub


