The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that subscription's ID.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-07 06:16
Updated : 2026-08-26 16:31
NVD link : CVE-2026-15214
Mitre link : CVE-2026-15214
CVE.ORG link : CVE-2026-15214
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
