Junglewise Threat Intelligence

CVE-2026-24527: Patterns in the cloud Autoship Cloud for WooCommerce missing authorization

CVE-2026-24527 · Severity: medium · CVSS 4.3 · Published 2026-05-25

Executive brief

The Autoship Cloud plugin for WooCommerce, which manages automated product subscriptions and recurring billing, contains a security flaw in its access control settings. An authenticated user with low-level permissions, such as a subscriber, could potentially perform actions they are not authorized to do. This could lead to unauthorized modifications of subscription data or settings, though it does not directly expose sensitive customer information.

Technical details

The Autoship Cloud for WooCommerce Subscription Products plugin (up to version 2.14.0) is vulnerable to broken access control due to missing authorization checks (CWE-862). An attacker authenticated with low-level privileges, such as a WordPress 'Subscriber' role, can exploit this flaw to execute functions or modify settings that should be restricted to higher-privileged users. The vulnerability stems from incorrectly configured access control security levels within the plugin's logic. While the CVSS score is 4.3 (Medium), the impact is limited to integrity (unauthorized changes) without direct impact on confidentiality or availability. As of the advisory date, no official patch has been confirmed.

Affected products

  • Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products n/a through 2.14.0

Timeline

  • 2025-12-27: other: Vulnerability reported by researcher Legion Hunter
  • 2026-05-25: disclosed: Vulnerability published by Patchstack
  • 2026-05-25: advisory: NVD published the CVE record

References