Executive brief
The 2Download Connector plugin for WordPress, which integrates checkout and subscription services, contains a security flaw that allows unauthorized access to customer data. An attacker can view sensitive information such as subscription status, product names, order IDs, and purchase dates without needing to log in. This could lead to the exposure of customer purchase history and business transaction details.
Technical details
The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to a Missing Authorization (CWE-862) flaw in versions up to and including 0.1.5. The vulnerability exists because the plugin fails to perform adequate authorization checks within its shortcode handling logic in Shortcodes.php. An unauthenticated remote attacker can exploit this to retrieve sensitive subscription details, including order IDs, product names, and expiry dates, for any customer. The issue is addressed in newer versions via improved authorization verification.
Affected products
- 2Download 2Download Connector for 2DL Hosted Checkout up to, and including, 0.1.5
Timeline
- 2026-06-19: disclosed
- 2026-06-19: advisory
References
- https://plugins.trac.wordpress.org/browser/2download-connector/tags/0.1.5/src/Shortcodes/Shortcodes.php
- https://plugins.trac.wordpress.org/browser/2download-connector/tags/0.1.5/src/Shortcodes/Shortcodes.php
- https://plugins.trac.wordpress.org/browser/2download-connector/tags/0.1.5/src/Shortcodes/Shortcodes.php
- https://plugins.trac.wordpress.org/browser/2download-connector/trunk/src/Shortcodes/Shortcodes.php
- https://plugins.trac.wordpress.org/browser/2download-connector/trunk/src/Shortcodes/Shortcodes.php
- https://plugins.trac.wordpress.org/browser/2download-connector/trunk/src/Shortcodes/Shortcodes.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3524785%402download-connector&new=3524785%402download-connector&sfp_email=&sfph_mail=