Impact
An IDOR flaw in the Subscriptions for WooCommerce WordPress plugin allows an authenticated customer to supply a subscription ID and receive the details of that subscription, including the product, status, and dates. The plugin fails to verify ownership of the subscription before displaying it, thus exposing confidential subscription data to other users. The vulnerability represents a direct breach of confidentiality for all customer data exposed through subscription records.
Affected Systems
Affected is the Subscriptions for WooCommerce plugin, with all releases prior to version 2.0.1. No additional vendor or product names were specified, and specific version ranges are limited to all versions below 2.0.1.
Risk and Exploitability
The flaw is exploitable by any authenticated customer, requiring no additional privileges or complex input. While no EPSS score is available and the vulnerability is not listed in the CISA KEV registry, the potential for widespread data exposure across all sites running the vulnerable plugin is significant. Attackers can enumerate subscription IDs and retrieve sensitive subscription details easily, threatening the privacy and trust model of e-commerce platforms that rely on the plugin.
OpenCVE Enrichment