CVE-2026-15215

WordPress · Subscriptions for WooCommerce

The Subscriptions for WooCommerce WordPress plugin is vulnerable to improper privilege management, potentially allowing authenticated users to perform unauthorized actions.

Executive summary

An improper privilege management vulnerability in the Subscriptions for WooCommerce WordPress plugin permits authenticated users to perform unauthorized actions beyond their intended permissions.

Vulnerability

This vulnerability is classified as improper privilege management (CWE-269), allowing an authenticated attacker to manipulate their privilege level within the context of the plugin.

Business impact

The CVSS score of 8.8 highlights the high severity of this flaw. Exploitation could lead to unauthorized access to subscription data, administrative control over store features, or the modification of sensitive customer transactions, directly impacting the financial and operational integrity of the e-commerce platform.

Remediation

Immediate Action: Update the Subscriptions for WooCommerce plugin to version 2.0.1 or later immediately.

Proactive Monitoring: Review WordPress user roles and permissions, and monitor the access logs for unauthorized attempts to access subscription-related administrative functions.

Compensating Controls: If an immediate update is not possible, temporarily deactivate the plugin to prevent exploitation until the patch can be applied.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the evidence of a proof-of-concept and the high CVSS score, organizations using this plugin must act with urgency. Applying the vendor-provided update is the only effective way to mitigate this privilege management flaw and ensure that user roles are correctly enforced.