Privilege Escalation Vulnerability in Subscriptions for WooCommerce by WordPress
CVE-2026-15414
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 August 2026
What is CVE-2026-15414?
The Subscriptions for WooCommerce plugin for WordPress contains a vulnerability that allows authenticated users with Contributor-level access and above to escalate their privileges to Administrator. This occurs due to the insufficient validation of the _wps_plan_user_role membership plan meta. The save_meta_boxes() function persists this role from $_POST without an appropriate allowlist, making it possible for malicious actors to manipulate the role assignment. The vulnerability is further compounded by the fact that the UI's role dropdown relies on client-side controls, which can be easily bypassed. Successful exploitation requires the active Pro companion plugin, which utilizes the stored role data to apply the elevated permissions.
Affected Version(s)
Subscriptions for WooCommerce 0 <= 2.0.0