Sceawere

Vulnerability Detail

CVE-2026-15214UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Subscriptions for WooCommerce Insecure Direct Object Reference

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
1d ago
Vendor
Unknown
Product
Subscriptions for WooCommerce
Attack Type
CWE-639 Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that subscription's ID.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-07T06:16:55.117Z",
  "pubdate": "2026-08-07T06:16:55.117Z",
  "executiveSummary": "An Insecure Direct Object Reference vulnerability exists in the Subscriptions for WooCommerce WordPress plugin before version 2.0.1.\nThe vulnerability allows authenticated customers to read sensitive subscription information belonging to other users, including subscribed products, subscription statuses, and active dates.\nThe flaw affects the Subscriptions for WooCommerce plugin within WordPress environments.\nThe risk implication involves unauthorized exposure of customer personally identifiable information and subscription metadata, potentially facilitating further social engineering or targeted attacks.\nAn attacker must possess a valid authenticated customer account on the target WordPress site to exploit this vulnerability.\nExploitation requires no elevated privileges beyond standard customer authentication, relying solely on manipulating the subscription identifier supplied in the request.",
  "technicalDetails": "The root cause of the vulnerability is an insufficient access control validation mechanism within the subscription details rendering functionality of the Subscriptions for WooCommerce plugin.\nSpecifically, the affected component fails to perform a cryptographic or logical authorization check to verify whether the currently authenticated requester owns or is explicitly authorized to view the subscription associated with the requested identifier.\nThe vulnerability is exposed when handling requests containing subscription IDs.\nThe attack flow proceeds as follows: First, an authenticated customer obtains or guesses a target subscription ID, which typically increments sequentially or is otherwise predictable. Second, the user transmits a crafted HTTP request to view the subscription details using the targeted subscription ID. Third, because the server-side code omits ownership verification, the application processes the request, retrieves the corresponding subscription record from the database, and renders the sensitive details—such as the subscribed product, status, and associated dates—back to the unauthorized requester.\nThe vulnerable software consists of versions of the Subscriptions for WooCommerce WordPress plugin prior to 2.0.1.\nAuthentication is required in the form of a standard customer account, but no administrative or high-privileged access is necessary.\nThe vulnerability is exploitable over the network wherever the WordPress application is accessible via HTTP or HTTPS.\nPost-exploitation impact includes the mass harvesting of customer subscription data, privacy violations, and the potential exposure of business intelligence regarding sales and customer retention metrics."
}
CVE-2026-15214: Subscriptions for WooCommerce Insecure Direct Object Reference (MEDIUM Severity, CVSS: 4.3) - Sceawere