CVE-2026-15215
Subscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Installation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution.
| Vendor | unknown |
| Product | subscriptions for woocommerce |
| Published | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown subscriptions for woocommerce
Be the first to know when new unknown vulnerabilities affecting unknown subscriptions for woocommerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Subscriptions for WooCommerce
0 < 2.0.1
References
Credits
Khaled Alenazi (Nxploited) WPScan