Impact
The Subscriptions for WooCommerce WordPress plugin allows a user with the Shop Manager role to trigger an AJAX action that installs and activates the plugin from a user‑supplied slug, even though the action is protected by a nonce and does not verify the user’s capability. This flaw permits arbitrary code execution on the site, giving the attacker full control of the WordPress installation.
Affected Systems
Any WordPress site running Subscriptions for WooCommerce plugin version earlier than 2.0.1 is affected. The vulnerability applies to all installations regardless of the specific configuration of the plugin, as the flaw exists in the core plugin code responsible for handling the AJAX request.
Risk and Exploitability
Since the Shop Manager role is a common default role in WordPress installs, many sites will have users with this capability. The lack of a capability check means that the flaw can be exploited by any such user without further assistance. The CVSS score of 8.8 indicates high severity exploitation potential. The EPSS score of <1% reflects a low but nonzero likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, yet the potential impact warrants immediate attention.
OpenCVE Enrichment