CVE-2026-15214 PUBLISHED

Subscriptions for WooCommerce < 2.0.1 - Subscriber+ Subscription Detail Disclosure via IDOR

Assigner: WPScan
Reserved: 09.07.2026 Published: 07.08.2026 Updated: 07.08.2026

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that subscription's ID.

Product Status

Vendor Unknown
Product Subscriptions for WooCommerce
Versions Default: unaffected
  • affected from 0 to 2.0.1 (excl.)

Credits

  • Muni Nitish Kumar Yaddala finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE