The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that subscription's ID.
History

Sat, 08 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpswings
Wpswings subscriptions For Woocommerce
Vendors & Products Wordpress
Wordpress wordpress
Wpswings
Wpswings subscriptions For Woocommerce

Fri, 07 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 07 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 07 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that subscription's ID.
Title Subscriptions for WooCommerce < 2.0.1 - Subscriber+ Subscription Detail Disclosure via IDOR
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-08-07T06:00:11.615Z

Updated: 2026-08-07T18:00:32.984Z

Reserved: 2026-07-09T08:04:27.828Z

Link: CVE-2026-15214

cve-icon Vulnrichment

Updated: 2026-08-07T18:00:24.186Z

cve-icon NVD

Status : Received

Published: 2026-08-07T06:16:55.117

Modified: 2026-08-07T18:17:08.470

Link: CVE-2026-15214

cve-icon Redhat

No data.