Impact
The Subscriptions for WooCommerce WordPress plugin allows a user with the Shop Manager role to trigger an AJAX action that installs and activates the plugin from a user-supplied slug, even though the action is protected by a nonce yet does not verify the user's capability. This results in arbitrary code execution on the site, giving the attacker full control of the WordPress installation.
Affected Systems
Any WordPress site running Subscriptions for WooCommerce plugin version earlier than 2.0.1 is affected. The vulnerability applies to all installations regardless of the specific configuration of the plugin, as the flaw exists in the core plugin code responsible for handling the AJAX request.
Risk and Exploitability
Since the Shop Manager role is a common default role in WordPress installs, many sites will have users with this capability. The lack of a capability check means that the flaw can be exploited by any such user without further assistance. No CVSS score was provided, but the consequence—remote code execution—indicates a high severity risk. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, but the potential impact warrants urgent attention.
OpenCVE Enrichment