Executive brief
The Subscriptions for WooCommerce plugin, used by online retailers to manage recurring billing, fails to verify security tokens when processing subscription cancellation requests. An attacker can trick a logged-in customer into canceling their active subscription by crafting a malicious request, leading to unintended loss of service and potential revenue impact for merchants.
Technical details
The vulnerability is a Cross-Site Request Forgery (CSRF) vulnerability in the subscription cancellation endpoint. The plugin does not validate a security token (nonce) on the request that processes subscription cancellations. An attacker can exploit this by crafting a malicious link or form that, when clicked or submitted by an authenticated customer, triggers an unauthorized cancellation of their subscription. This requires the victim to be logged in and tricked into visiting a malicious page, but no additional authentication or authorization checks prevent the cancellation. The vulnerability affects versions before 2.0.3, which contains the fix.
Affected products
- WP Desk Subscriptions for WooCommerce before 2.0.3
Timeline
- 2026-09-14: disclosed
- 2026-09-16: patched: version 2.0.3 contains the fix