Description
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that subscription's ID.
Published: 2026-08-07
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An IDOR flaw in the Subscriptions for WooCommerce WordPress plugin allows an authenticated customer to supply a subscription ID and receive the details of that subscription, including the product, status, and dates. The plugin fails to verify ownership of the subscription before displaying it, thus exposing confidential subscription data to other users. The vulnerability represents a direct breach of confidentiality for all customer data exposed through subscription records.

Affected Systems

Affected is the Subscriptions for WooCommerce plugin, with all releases prior to version 2.0.1. No additional vendor or product names were specified, and specific version ranges are limited to all versions below 2.0.1.

Risk and Exploitability

The flaw is exploitable by any authenticated customer, requiring no additional privileges or complex input. While no EPSS score is available and the vulnerability is not listed in the CISA KEV registry, the potential for widespread data exposure across all sites running the vulnerable plugin is significant. Attackers can enumerate subscription IDs and retrieve sensitive subscription details easily, threatening the privacy and trust model of e-commerce platforms that rely on the plugin.

Generated by OpenCVE AI on August 7, 2026 at 07:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Subscriptions for WooCommerce to version 2.0.1 or newer
  • Ensure the plugin implements an ownership check that verifies the current user is the subscription owner before rendering details
  • Verify that user accounts cannot request arbitrary subscription IDs by adding input validation or access control checks in the subscription detail endpoint

Generated by OpenCVE AI on August 7, 2026 at 07:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 07 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that subscription's ID.
Title Subscriptions for WooCommerce < 2.0.1 - Subscriber+ Subscription Detail Disclosure via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-07T06:00:11.615Z

Reserved: 2026-07-09T08:04:27.828Z

Link: CVE-2026-15214

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T07:30:09Z

Weaknesses