CVE-2026-87860
Subscriptions for WooCommerce < 2.0.3 - Subscription Cancellation via CSRF
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make a logged-in customer cancel their own active subscription through a crafted request they are tricked into making.
| Vendor | unknown |
| Product | subscriptions for woocommerce |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown subscriptions for woocommerce
Be the first to know when new unknown vulnerabilities affecting unknown subscriptions for woocommerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Subscriptions for WooCommerce
0 < 2.0.3
References
Credits
Karthik Ramakrishnan WPScan