Missing Authorization Vulnerability in Subscriptions for WooCommerce Plugin by WordPress
CVE-2026-15397
7.2HIGH
What is CVE-2026-15397?
The Subscriptions for WooCommerce plugin for WordPress has a vulnerability that allows authenticated users with shop manager-level access or higher to exploit a missing authorization check. Specifically, the plugin's wps_sfw_install_plugin_configuration AJAX handler does not properly validate whether a user is authorized to perform specific actions. This oversight permits these users to install and activate arbitrary plugins from WordPress.org, potentially leading to unauthorized modifications or installations that compromise site security.
Affected Version(s)
Subscriptions for WooCommerce 0 <= 2.0.0