Sceawere
Vulnerability Detail
CVE-2026-39762UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Broken Access Control
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 16h ago
- Vendor
- Patterns In The Cloud
- Product
- Autoship Cloud for WooCommerce Subscription Products
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Broken Access Control in Autoship Cloud for WooCommerce Subscription Products <= 2.17.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-06T09:17:48.160Z",
"pubdate": "2026-10-06T09:17:48.160Z",
"executiveSummary": "The Autoship Cloud for WooCommerce Subscription Products plugin, in versions up to and including 2.17.0, is affected by an unauthenticated broken access control vulnerability.\nThis flaw allows remote, unauthenticated attackers to perform unauthorized actions within the plugin's ecosystem without requiring valid session tokens or administrative privileges.\nThe vulnerability stems from improper authorization checks on critical endpoints, enabling unauthorized modification or retrieval of subscription-related data.\nThe risk is critical, as it bypasses standard WooCommerce security layers, potentially leading to unauthorized data exposure, subscription manipulation, or escalation of privileges within the WordPress environment.\nExploitation requires network access to the affected site; no specific user interaction is necessitated to trigger the vulnerability. Given the nature of the plugin, successful exploitation could facilitate the unauthorized modification of customer subscription settings or sensitive account configurations.",
"technicalDetails": "The vulnerability resides in the core access control logic of the Autoship Cloud for WooCommerce Subscription Products plugin. In versions <= 2.17.0, the plugin fails to implement robust permission verification on specific REST API endpoints or AJAX handlers responsible for managing subscription products and customer data.\nThe root cause is the absence of appropriate capability checks (e.g., current_user_can()) or nonces when executing server-side logic related to subscription management. The application logic assumes that requests directed at these specific endpoints are inherently authorized, failing to validate the session state or the user's role before processing the request payload.\nAttack flow: An unauthenticated attacker identifies the vulnerable API endpoint or exposed controller within the plugin's codebase. By crafting a malicious HTTP request (typically a POST or GET request) targeting these unprotected functions, the attacker can manipulate the plugin's internal state. Because the backend fails to verify identity, the application processes the request as if it originated from a legitimate, authorized user.\nTechnical exploitation typically involves sending a request to the server with manipulated parameters that dictate subscription status, customer ID, or other internal object identifiers. Since there is no validation of the requester's context, the server-side code executes the requested function—such as updating or deleting subscription data—based on the attacker's supplied parameters.\nNetwork exposure is high, as these endpoints are often publicly accessible via the standard WooCommerce/WordPress REST API path. The lack of proper authorization checks means an attacker can bypass the intended plugin security model entirely.\nPost-exploitation impact includes the unauthorized modification of WooCommerce subscription entities, potentially allowing attackers to change subscription statuses, alter billing intervals, or access customer data associated with subscriptions. This can result in financial discrepancies, unauthorized access to subscription services, or, depending on the plugin's integration with the broader WordPress ecosystem, further privilege escalation if the data returned or modified influences administrative routines."
}