๐Ÿ” CVE Alert

CVE-2026-15215

UNKNOWN 0.0

Subscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Installation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution.

Vendor unknown
Product subscriptions for woocommerce
Published Aug 7, 2026
Stay Ahead of the Next One

Get instant alerts for unknown subscriptions for woocommerce

Be the first to know when new unknown vulnerabilities affecting unknown subscriptions for woocommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Subscriptions for WooCommerce
0 < 2.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/dad30b9f-1c50-4d0e-baa0-9bce2f5a7db5/

Credits

Khaled Alenazi (Nxploited) WPScan