Executive brief
Subscriptions for WooCommerce is a WordPress plugin used to manage recurring payments and subscription-based products on e-commerce sites. A security flaw in versions 1.9.5 and earlier allows unauthorized individuals to perform actions that should be restricted to administrators or specific users. This could lead to unauthorized changes to subscription data or store settings, potentially disrupting business operations and revenue.
Technical details
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862) in versions up to and including 1.9.5. This allows an unauthenticated remote attacker to execute functions or modify settings that should be restricted. The vulnerability has a CVSS score of 7.5, reflecting high integrity impact despite no direct confidentiality or availability impact reported. The issue is resolved in version 1.9.6.
Affected products
- WP Swings Subscriptions for WooCommerce <= 1.9.5
Timeline
- 2026-05-06: other: Reported by Jakub Herman
- 2026-06-25: advisory: Patchstack advisory published
- 2026-06-26: disclosed: NVD publication date