CVE-2026-15215 PUBLISHED

Subscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Installation

Assigner: WPScan
Reserved: 09.07.2026 Published: 07.08.2026 Updated: 07.08.2026

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution.

Product Status

Vendor Unknown
Product Subscriptions for WooCommerce
Versions Default: unaffected
  • affected from 0 to 2.0.1 (excl.)

Credits

  • Khaled Alenazi (Nxploited) finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE