Remote Code Execution Vulnerability in WooCommerce Subscriptions Plugin by WooCommerce
CVE-2026-15215
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 August 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-15215?
The Subscriptions for WooCommerce plugin for WordPress has a security flaw where it fails to validate user permissions when installing and activating the plugin via a nonce-protected AJAX action. This oversight allows users with the Shop Manager role, who ordinarily lack sufficient management capabilities, to exploit the vulnerability and execute arbitrary code. As a result, unauthorized actions could be performed, compromising the integrity and security of the WordPress site.
Affected Version(s)
Subscriptions for WooCommerce 0 < 2.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.