CVE-2026-15214

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that subscription's ID.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-07 06:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-15214

Mitre link : CVE-2026-15214

CVE.ORG link : CVE-2026-15214


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key