CVE-2025-69347
8.5Convers Lab · WPSubscription
An authorization bypass vulnerability in the Convers Lab WPSubscription plugin allows unauthenticated attackers to manipulate user-controlled keys to escalate access.
Executive summary
The Convers Lab WPSubscription plugin contains a critical authorization bypass vulnerability that allows unauthenticated attackers to gain unauthorized access to subscription data.
Vulnerability
The flaw is an authorization bypass (CWE-639) caused by insecure handling of user-controlled keys, which allows an unauthenticated attacker to interact with the plugin without proper permission checks.
Business impact
Successful exploitation of this vulnerability could lead to significant unauthorized access to sensitive subscription data and potential modification of account settings. Given the CVSS score of 8.5, this high-severity flaw poses a substantial risk to data confidentiality and integrity, potentially leading to regulatory compliance issues and loss of customer trust.
Remediation
Immediate Action: Since a specific patch version is currently unknown, administrators should immediately deactivate or uninstall the WPSubscription plugin until a secure update is released by the vendor.
Proactive Monitoring: Review web server and WordPress access logs for anomalous requests targeting subscription-related endpoints or unusual patterns involving user-controlled parameters.
Compensating Controls: Deploy a Web Application Firewall (WAF) rule to block unauthorized attempts to access plugin-specific endpoints, specifically focusing on requests that manipulate query parameters associated with user keys.
Exploitation status
Public Exploit Available: No confirmed public exploit is available.
Analyst recommendation
This vulnerability represents a significant security risk due to the potential for unauthenticated access. We strongly recommend that organizations using the WPSubscription plugin prioritize removing the component until the vendor provides a verified fix, as standard security controls may be insufficient to prevent exploitation by determined actors.
Sources
Originally found and disclosed by Jitlada | Patchstack Bug Bounty Program, per the CVE Program record.