Impact
The Subscriptions for WooCommerce plugin contains a missing authorization check in the wps_sfw_install_plugin_configuration AJAX handler. Authenticated users with shop manager or higher privileges can trigger the installation and activation of any WordPress.org plugin through this endpoint. This allows an attacker to inject arbitrary code and gain further control over the site, effectively elevating privileges and compromising site integrity.
Affected Systems
WordPress sites running WPSWings Subscriptions for WooCommerce version 2.0.0 or earlier are affected. No specific version range beyond the stated up‑to‑2.0.0 is provided in the advisory.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity vulnerability. The EPSS score is less than 1%, but the attack does not require any additional conditions beyond authenticated shop manager access. Because shop managers are typically granted on‑site operational roles, the exploitation potential is significant. The vulnerability is not listed in CISA’s KEV catalog, but its impact and broad availability of the required role make it a serious threat in practice.
OpenCVE Enrichment