Impact
The Subscriptions for WooCommerce WordPress plugin version 2.0.3 or older fails to validate the security token when processing a subscription cancellation request. This missing validation allows a logged‑in customer to be tricked into sending a crafted request that cancels their own active subscription. The consequence is loss of recurring revenue and interruption of service for the affected customer.
Affected Systems
Any WordPress site running the Subscriptions for WooCommerce plugin below version 2.0.3 is vulnerable. The plugin is the affected product; no specific CPE is supplied beyond the vendor and product name. All users of the plugin at these versions are at risk.
Risk and Exploitability
The exploit is a classic CSRF attack that relies on the user being authenticated and the attacker delivering a forged request. The EPSS score of less than 1% and absence from the CISA KEV catalog suggest a low frequency of real‑world exploitation, however the impact can be significant for merchants relying on automated subscription revenue. The CVSS score is not provided, but the vulnerability likely maps to moderate to high severity given the loss of revenue.
OpenCVE Enrichment