Description
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. This makes it possible for authenticated attackers, with shop manager-level access and above, to install and activate arbitrary WordPress.org plugins.
Published: 2026-07-30
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Subscriptions for WooCommerce plugin contains a missing authorization check in the wps_sfw_install_plugin_configuration AJAX handler. Authenticated users with shop manager or higher privileges can trigger the installation and activation of any WordPress.org plugin through this endpoint. This allows an attacker to inject arbitrary code and gain further control over the site, effectively elevating privileges and compromising site integrity.

Affected Systems

WordPress sites running WPSWings Subscriptions for WooCommerce version 2.0.0 or earlier are affected. No specific version range beyond the stated up‑to‑2.0.0 is provided in the advisory.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity vulnerability. The EPSS score is less than 1%, but the attack does not require any additional conditions beyond authenticated shop manager access. Because shop managers are typically granted on‑site operational roles, the exploitation potential is significant. The vulnerability is not listed in CISA’s KEV catalog, but its impact and broad availability of the required role make it a serious threat in practice.

Generated by OpenCVE AI on August 3, 2026 at 10:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Subscriptions for WooCommerce to a version newer than 2.0.0, if an update is available
  • If an update is not possible, review the shop manager role and remove or constrain the capability that allows plugin installation
  • Disable or restrict the wps_sfw_install_plugin_configuration AJAX action, ensuring it requires a higher capability or is not exposed publicly
  • After any incident, audit installed plugins for unexpected or malicious code

Generated by OpenCVE AI on August 3, 2026 at 10:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpswings
Wpswings subscriptions For Woocommerce
Vendors & Products Wordpress
Wordpress wordpress
Wpswings
Wpswings subscriptions For Woocommerce

Thu, 30 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. This makes it possible for authenticated attackers, with shop manager-level access and above, to install and activate arbitrary WordPress.org plugins.
Title Subscriptions for WooCommerce <= 2.0.0 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation via wps_sfw_install_plugin_configuration AJAX Action
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
Wpswings Subscriptions For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-30T13:57:54.797Z

Reserved: 2026-07-10T13:23:25.836Z

Link: CVE-2026-15397

cve-icon Vulnrichment

Updated: 2026-07-30T13:57:49.768Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T12:17:26.927

Modified: 2026-07-30T14:16:47.217

Link: CVE-2026-15397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:00:03Z

Weaknesses