Authorization Bypass in WPSubscription Plugin by Convers Lab
CVE-2025-69347
8.6HIGH
What is CVE-2025-69347?
The WPSubscription plugin by Convers Lab has a vulnerability that allows users to bypass authorization controls through user-controlled keys. This misconfiguration can lead to unauthorized access to protected resources, potentially exposing sensitive data to unauthorized users. This issue affects all versions up to and including 1.8.10, highlighting the importance of proper access control mechanisms in plugin development.
Affected Version(s)
WPSubscription 0 <= 1.8.10