VYPR
Medium severity4.3NVD Advisory· Published May 25, 2026

CVE-2026-24527

CVE-2026-24527

Description

Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.14.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A missing authorization vulnerability in Autoship Cloud for WooCommerce Subscription Products allows unprivileged users to access restricted functionality.

Vulnerability

Missing Authorization vulnerability in the Autoship Cloud for WooCommerce Subscription Products plugin for WordPress allows exploitation of incorrectly configured access control security levels. The issue affects versions from n/a through 2.14.0 [1]. The vulnerability is classified as a Broken Access Control issue, meaning a missing authorization check in a function could allow an unprivileged user to execute a higher privileged action [1].

Exploitation

Attackers need no special privileges beyond standard unauthenticated or low-privileged access to a WordPress site running the vulnerable plugin version. The exact sequence of steps is not disclosed in the available references, but the flaw can be triggered by sending crafted requests to the affected plugin's endpoints. This vulnerability is known to be used in mass-exploit campaigns against thousands of websites regardless of traffic size or popularity [1].

Impact

Successful exploitation allows an attacker to perform unauthorized actions due to the missing access control checks. The primary impact is a breach of confidentiality and integrity, potentially leading to unauthorized access to subscription data, modification of settings, or other actions normally restricted to higher-privileged users. The specific privilege level gained depends on the vulnerable function, but the CVSS v3 score of 4.3 indicates a medium-severity impact [1].

Mitigation

The vendor has not yet released a patched version. The immediate action is to update the plugin once a fixed version becomes available. If unable to update, users should contact their hosting provider or web developer for assistance. The plugin is not listed on the CISA KEV as of the publication date [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.