PT-2026-66456 · Wp Swings+1 · Woocommerce Subscriptions
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Subscriptions for WooCommerce versions prior to 2.0.1
Description
Missing authorization in the plugin allows authenticated attackers with shop manager-level access or higher to install and activate arbitrary WordPress.org plugins. This occurs because the plugin fails to properly verify user authorization when processing requests through the
wps sfw install plugin configuration AJAX handler.Recommendations
Update Subscriptions for WooCommerce to a version later than 2.0.0.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Woocommerce Subscriptions