Description
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution.
Published: 2026-08-07
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Subscriptions for WooCommerce WordPress plugin allows a user with the Shop Manager role to trigger an AJAX action that installs and activates the plugin from a user‑supplied slug, even though the action is protected by a nonce and does not verify the user’s capability. This flaw permits arbitrary code execution on the site, giving the attacker full control of the WordPress installation.

Affected Systems

Any WordPress site running Subscriptions for WooCommerce plugin version earlier than 2.0.1 is affected. The vulnerability applies to all installations regardless of the specific configuration of the plugin, as the flaw exists in the core plugin code responsible for handling the AJAX request.

Risk and Exploitability

Since the Shop Manager role is a common default role in WordPress installs, many sites will have users with this capability. The lack of a capability check means that the flaw can be exploited by any such user without further assistance. The CVSS score of 8.8 indicates high severity exploitation potential. The EPSS score of <1% reflects a low but nonzero likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, yet the potential impact warrants immediate attention.

Generated by OpenCVE AI on August 7, 2026 at 22:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Subscriptions for WooCommerce to version 2.0.1 or later in order to apply the vendor’s remediation for this flaw.
  • If an upgrade is not immediately possible, remove the Shop Manager role from users or reduce its permissions so that they cannot trigger plugin installations.
  • Validate user capabilities on the server side before performing any plugin installation and ensure that nonces cannot be fabricated by unauthorized users.

Generated by OpenCVE AI on August 7, 2026 at 22:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpswings
Wpswings subscriptions For Woocommerce
Vendors & Products Wordpress
Wordpress wordpress
Wpswings
Wpswings subscriptions For Woocommerce

Fri, 07 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276
CWE-284

Fri, 07 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276
CWE-284

Fri, 07 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution.
Title Subscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Installation
References

Subscriptions

Wordpress Wordpress
Wpswings Subscriptions For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-07T18:12:36.214Z

Reserved: 2026-07-09T08:04:31.124Z

Link: CVE-2026-15215

cve-icon Vulnrichment

Updated: 2026-08-07T18:12:31.495Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T06:16:55.227

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-15215

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:53:34Z

Weaknesses
  • CWE-269

    Improper Privilege Management