Unknown · 2Download Connector For 2Dl Hosted Checkout · CVE-2026-6798
**Name of the Vulnerable Software and Affected Versions**
2Download Connector for 2DL Hosted Checkout versions prior to 0.1.6
**Description**
The plugin fails to properly verify user authorization before performing specific actions. This allows unauthenticated attackers to access arbitrary customer subscription data, including subscription status, product names, order IDs, purchase dates, and expiry dates.
**Recommendations**
Update to a version later than 0.1.5.