Cross-Site Request Forgery Vulnerability in Convers Lab WPSubscription
CVE-2026-24554
4.3MEDIUM
What is CVE-2026-24554?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WPSubscription plugin developed by Convers Lab. This security flaw allows malicious actors to perform unauthorized actions on behalf of a user without their consent. The vulnerability affects all versions of WPSubscription up to and including version 1.9.1, exposing users to potential risks including unauthorized subscription modifications.
Affected Version(s)
WPSubscription <= 1.9.1