Junglewise Threat Intelligence

CVE-2026-15397: WP Swings Subscriptions for WooCommerce missing authorization in AJAX handler

CVE-2026-15397 · Severity: high · CVSS 7.2 · Published 2026-07-30

Executive brief

The Subscriptions for WooCommerce plugin for WordPress, which manages recurring payments for online stores, contains a security flaw that allows unauthorized plugin installations. An attacker with Shop Manager level access or higher can exploit this to install and activate any plugin from the WordPress.org repository. This could lead to a full site takeover or the introduction of malicious software that compromises customer data and store operations.

Technical details

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to a Missing Authorization flaw (CWE-862) within the wps_sfw_install_plugin_configuration AJAX handler. The root cause is a failure to properly verify user permissions before executing plugin installation and activation actions. An authenticated attacker with Shop Manager-level privileges or higher can leverage this vulnerability to install and activate any arbitrary plugin from the WordPress.org repository. This could be used as a vector for further site compromise or remote code execution depending on the installed plugin's capabilities. The vulnerability is present in all versions up to and including 2.0.0.

Affected products

  • WP Swings Subscriptions for WooCommerce up to, and including, 2.0.0

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: advisory

References

Related threats