CVE-2026-1926 PUBLISHED

Subscriptions for WooCommerce <= 1.9.2 - Missing Authorization to Unauthenticated Arbitrary Subscription Cancellation

Assigner: Wordfence
Reserved: 04.02.2026 Published: 18.03.2026 Updated: 18.03.2026

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wps_sfw_admin_cancel_susbcription() function in all versions up to, and including, 1.9.2. This is due to the function being hooked to the init action without any authentication or authorization checks, and only performing a non-empty check on the nonce parameter without actually validating it via wp_verify_nonce(). This makes it possible for unauthenticated attackers to cancel any active WooCommerce subscription by sending a crafted GET request with an arbitrary nonce value via the wps_subscription_id parameter.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 5.3

Product Status

Vendor wpswings
Product Subscriptions for WooCommerce
Versions Default: unaffected
  • affected from * to 1.9.2 (incl.)

Credits

  • shrikant bhosale finder

References

Problem Types

  • CWE-862 Missing Authorization CWE