Executive brief
The Recurio plugin for WooCommerce, which manages subscription-based products on WordPress sites, contains a security flaw that allows high-level users to run unauthorized database commands. An attacker with shop manager or administrator credentials could exploit this to steal sensitive information from the website's database. This could lead to the exposure of customer data or internal site configuration details.
Technical details
A generic SQL injection vulnerability exists in the Recurio – Ultimate Subscription for WooCommerce plugin for WordPress due to insufficient escaping of the 'data' parameter and a lack of SQL query preparation in the subscription engine. The flaw is located within the 'class-subscription-engine.php' component. An authenticated attacker with Shop Manager-level permissions or higher can inject malicious SQL fragments into existing queries. This allows for the unauthorized extraction of sensitive data from the WordPress database. The vulnerability is addressed in versions following 1.1.3.
Affected products
- devitemsllc Recurio – Ultimate Subscription for WooCommerce <= 1.1.3
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory
References
- https://plugins.trac.wordpress.org/browser/recurio/tags/1.1.2/includes/core/class-subscription-engine.php
- https://plugins.trac.wordpress.org/browser/recurio/tags/1.1.2/includes/core/class-subscription-engine.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3593971%40recurio&new=3593971%40recurio
- https://www.wordfence.com/threat-intel/vulnerabilities/id/4b34ad23-246e-42ba-89de-5985043848be?source=cve