VYPR

Woocommerce Subscriptions

by WordPress

CVEs (11)

  • CVE-2026-18391CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a…

  • CVE-2026-15215HigAug 7, 2026
    risk 0.57cvss 8.8epss 0.00

    The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users…

  • CVE-2026-15414HigAug 1, 2026
    risk 0.57cvss 8.8epss 0.00

    The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that…

  • CVE-2026-24372HigMar 25, 2026
    risk 0.49cvss 7.5epss 0.00

    Authentication Bypass by Spoofing vulnerability in WP Swings Subscriptions for WooCommerce subscriptions-for-woocommerce allows Input Data Manipulation.This issue affects Subscriptions for WooCommerce: from n/a through <= 1.8.10.

  • CVE-2019-18834MedJul 23, 2020
    risk 0.40cvss 6.1epss 0.02

    Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Billing Details are mishandled in WCS_Admin_Post_Types in class-wcs-admin-post-types.php.

  • CVE-2026-15211MedAug 7, 2026
    risk 0.38cvss 5.9epss 0.00

    The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed on the WooCommerce order-received flow: it captures a client-supplied token and marks the order paid whenever the…

  • CVE-2026-1926MedMar 18, 2026
    risk 0.34cvss 5.3epss 0.00

    The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wps_sfw_admin_cancel_susbcription()` function in all versions up to, and including, 1.9.2. This is due to the function being hooked…

  • CVE-2026-15214MedAug 7, 2026
    risk 0.28cvss 4.3epss 0.00

    The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product,…

  • CVE-2023-50850MedDec 31, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Woo WooCommerce Subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Subscriptions: from n/a before 5.8.0.

  • CVE-2026-15397HigJul 30, 2026
    risk 0.00cvss 7.2epss 0.00

    The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration…

  • CVE-2026-56061HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.