Impact
The Subscriptions for WooCommerce WordPress plugin before version 2.0.3 fails to validate the shared secret protecting a REST API endpoint, allowing any unauthenticated user to retrieve the store’s full list of subscriptions. An attacker can obtain customer usernames, product names, recurring amounts and payment dates, resulting in a confidential data breach. This vulnerability represents an improper authorization failure (CWE‑285) and a sensitive data exposure (CWE‑200).
Affected Systems
Any WordPress site running the Subscriptions for WooCommerce plugin with a version older than 2.0.3 is affected. No other vendor or product details are listed, so the risk applies solely to installations of this plugin that have not yet been updated.
Risk and Exploitability
The EPSS score is below 1 %, indicating a very low probability of exploitation as reported at the time of analysis. The vulnerability is not cataloged in CISA’s KEV list and its CVSS metrics are not provided, but the fact that the endpoint is exposed to anyone on the network means a remote attacker could deploy a simple HTTP request to harvest subscription data. As the threat does not require elevated privileges or advanced capabilities, the potential impact is serious only if the exploit is discovered.
OpenCVE Enrichment