Privilege Escalation Vulnerability in Subscriptions for WooCommerce by WordPress
CVE-2026-15414

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 August 2026

What is CVE-2026-15414?

The Subscriptions for WooCommerce plugin for WordPress contains a vulnerability that allows authenticated users with Contributor-level access and above to escalate their privileges to Administrator. This occurs due to the insufficient validation of the _wps_plan_user_role membership plan meta. The save_meta_boxes() function persists this role from $_POST without an appropriate allowlist, making it possible for malicious actors to manipulate the role assignment. The vulnerability is further compounded by the fact that the UI's role dropdown relies on client-side controls, which can be easily bypassed. Successful exploitation requires the active Pro companion plugin, which utilizes the stored role data to apply the elevated permissions.

Affected Version(s)

Subscriptions for WooCommerce 0 <= 2.0.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.