Impact
A flaw in the discourse‑subscriptions plugin lets a user purchase a lower tier subscription yet assign themselves the benefits of a higher tier. The vulnerability falls under Improper Authorization (CWE‑269 and CWE‑285) and permits an attacker to gain additional features or access that the higher tier normally protects, potentially giving them unauthorized privilege or revenue‑based benefits.
Affected Systems
The vulnerability affects Discourse installations using the discourse‑subscriptions plugin. Version ranges impacted are 2026.1.0 up to, but not including, 2026.1.3; 2026.2.0 up to, but not including, 2026.2.2; and 2026.3.0 up to, but not including, 2026.3.0. The fix was released in 2026.1.3, 2026.2.2, and 2026.3.0.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. No EPSS data is available, and the issue is not listed in the CISA KEV catalog. The attack is likely executable by any authenticated user who can interact with the subscription interface, as the vulnerability involves self‑assignment of higher tier privileges. Therefore the risk is real, albeit moderate, and worth addressing promptly.
OpenCVE Enrichment