Sceawere

Vulnerability Detail

CVE-2026-39762UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Broken Access Control

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
16h ago
Vendor
Patterns In The Cloud
Product
Autoship Cloud for WooCommerce Subscription Products
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Broken Access Control in Autoship Cloud for WooCommerce Subscription Products <= 2.17.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-06T09:17:48.160Z",
  "pubdate": "2026-10-06T09:17:48.160Z",
  "executiveSummary": "The Autoship Cloud for WooCommerce Subscription Products plugin, in versions up to and including 2.17.0, is affected by an unauthenticated broken access control vulnerability.\nThis flaw allows remote, unauthenticated attackers to perform unauthorized actions within the plugin's ecosystem without requiring valid session tokens or administrative privileges.\nThe vulnerability stems from improper authorization checks on critical endpoints, enabling unauthorized modification or retrieval of subscription-related data.\nThe risk is critical, as it bypasses standard WooCommerce security layers, potentially leading to unauthorized data exposure, subscription manipulation, or escalation of privileges within the WordPress environment.\nExploitation requires network access to the affected site; no specific user interaction is necessitated to trigger the vulnerability. Given the nature of the plugin, successful exploitation could facilitate the unauthorized modification of customer subscription settings or sensitive account configurations.",
  "technicalDetails": "The vulnerability resides in the core access control logic of the Autoship Cloud for WooCommerce Subscription Products plugin. In versions <= 2.17.0, the plugin fails to implement robust permission verification on specific REST API endpoints or AJAX handlers responsible for managing subscription products and customer data.\nThe root cause is the absence of appropriate capability checks (e.g., current_user_can()) or nonces when executing server-side logic related to subscription management. The application logic assumes that requests directed at these specific endpoints are inherently authorized, failing to validate the session state or the user's role before processing the request payload.\nAttack flow: An unauthenticated attacker identifies the vulnerable API endpoint or exposed controller within the plugin's codebase. By crafting a malicious HTTP request (typically a POST or GET request) targeting these unprotected functions, the attacker can manipulate the plugin's internal state. Because the backend fails to verify identity, the application processes the request as if it originated from a legitimate, authorized user.\nTechnical exploitation typically involves sending a request to the server with manipulated parameters that dictate subscription status, customer ID, or other internal object identifiers. Since there is no validation of the requester's context, the server-side code executes the requested function—such as updating or deleting subscription data—based on the attacker's supplied parameters.\nNetwork exposure is high, as these endpoints are often publicly accessible via the standard WooCommerce/WordPress REST API path. The lack of proper authorization checks means an attacker can bypass the intended plugin security model entirely.\nPost-exploitation impact includes the unauthorized modification of WooCommerce subscription entities, potentially allowing attackers to change subscription statuses, alter billing intervals, or access customer data associated with subscriptions. This can result in financial discrepancies, unauthorized access to subscription services, or, depending on the plugin's integration with the broader WordPress ecosystem, further privilege escalation if the data returned or modified influences administrative routines."
}
CVE-2026-39762: Unauthenticated Broken Access Control (MEDIUM Severity, CVSS: 6.5) | Sceawere