Impact
The Subscriptions for WooCommerce WordPress plugin version prior to 2.0.1 contains an IDOR flaw that allows an authenticated customer to supply a subscription identifier and obtain full details for that subscription, including product, status, and dates. This represents a breach of confidentiality and satisfies the CWE‑639 (Authorization Bypass Through User‑Controlled Key) weakness, as the system fails to verify that the requester owns the subscription before rendering it.
Affected Systems
All installations of the Subscriptions for WooCommerce plugin with versions earlier than 2.0.1 are affected. No additional vendor or product names are specified, and the impact extends to every customer record managed by the vulnerable plugin.
Risk and Exploitability
The vulnerability can be exploited by any authenticated user with access to the site; the attack vector is inferred to be an authenticated web session that submits a subscription ID. Because the EPSS score is reported as < 1% and the issue is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is low, yet the moderate CVSS score of 4.3 indicates a potential for significant privacy loss if the flaw is leveraged. The flaw would allow a malicious user to enumerate subscription IDs and read confidential subscription data across all customers on a site.
OpenCVE Enrichment