The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-276 CWE-284 |
Fri, 07 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution. | |
| Title | Subscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Installation | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-07T06:00:11.800Z
Reserved: 2026-07-09T08:04:31.124Z
Link: CVE-2026-15215
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T07:30:09Z