plugin

Subscriptions For Woocommerce Vulnerabilities

10 known security issues reported for the Subscriptions For Woocommerce WordPress plugin. Most recent disclosed Aug 3, 2026.

3 high 7 medium

Running Subscriptions For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Subscriptions for WooCommerce <= 2.0.0 - Unauthenticated Payment Verification Bypass

medium

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Payment Verification Bypass in versions up to, and including, 2.0.0. This is due to missing validation binding the PayPal capture token returned in the GET parameter to the PayPal order ID actually created for the WooCommerce order at checkout. Thi...

CVSS:
5.3
Affected:
up to 2.0.0
Fixed in:
2.0.1
Disclosed:
Aug 3, 2026

CVE-2026-15211 on NVD →

Subscriptions for WooCommerce <= 2.0.0 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation

medium

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 2.0.0. This is due to a missing capability check on the wps_sfw_install_plugin_configuration() AJAX function, allowing users with manage_woocommerce (Shop Manager) but without install_plugins/ac...

CVSS:
4.7
Affected:
up to 2.0.0
Fixed in:
2.0.1
Disclosed:
Aug 3, 2026

CVE-2026-15215 on NVD →

Subscriptions for WooCommerce <= 2.0.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Subscription Detail Disclosure

medium

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.0. This is due to missing ownership verification on the wps-show-subscription parameter before rendering subscription detail templates. This makes it possible for authenticated...

CVSS:
4.3
Affected:
up to 2.0.0
Fixed in:
2.0.1
Disclosed:
Aug 3, 2026

CVE-2026-15214 on NVD →

Subscriptions for WooCommerce <= 2.0.0 - Authenticated (Contributor+) Privilege Escalation via '_wps_plan_user_role' Membership Plan Meta

high

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged roles — the only val...

CVSS:
8.8
Affected:
up to 2.0.0
Fixed in:
2.0.1
Disclosed:
Jul 31, 2026

CVE-2026-15414 on NVD →

Subscriptions for WooCommerce <= 2.0.0 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation via wps_sfw_install_plugin_configuration AJAX Action

high

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. This makes it possible for...

CVSS:
7.2
Affected:
up to 2.0.0
Fixed in:
2.0.1
Disclosed:
Jul 29, 2026

CVE-2026-15397 on NVD →

Subscriptions for WooCommerce <= 1.9.5 - Missing Authorization

medium

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.9.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.9.5
Fixed in:
1.9.6
Disclosed:
Jun 25, 2026

CVE-2026-56061 on NVD →

Subscriptions for WooCommerce - Missing Authorization to Unauthenticated Arbitrary Subscription Cancellation vulnerability

medium

Missing Authorization to Unauthenticated Arbitrary Subscription Cancellation vulnerability

CVSS:
5.3
Affected:
up to 1.9.2
Fixed in:
1.9.3
Disclosed:
Mar 18, 2026

Subscriptions for WooCommerce <= 1.9.2 - Missing Authorization to Unauthenticated Arbitrary Subscription Cancellation

medium

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wps_sfw_admin_cancel_susbcription()` function in all versions up to, and including, 1.9.2. This is due to the function being hooked to the `init` action without any authent...

CVSS:
5.3
Affected:
up to 1.9.2
Fixed in:
1.9.3
Disclosed:
Mar 17, 2026

CVE-2026-1926 on NVD →

Subscriptions for WooCommerce - Bypass Vulnerability vulnerability

high

Bypass Vulnerability vulnerability

CVSS:
7.5
Affected:
up to 1.8.10
Fixed in:
1.9.0
Disclosed:
Mar 13, 2026

Subscriptions for WooCommerce <= 1.8.10 - Missing Authorization

medium

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.8.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.8.10
Fixed in:
1.9.0
Disclosed:
Mar 13, 2026

CVE-2026-24372 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database