CVE-2026-15214: Subscriptions for WooCommerce < 2.0.1 - Subscriber+ Subscription Detail Disclosure via IDOR
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that subscription's ID.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15214?
CVE-2026-15214 has a risk score of 38, indicating a moderate severity level.
How do I fix CVE-2026-15214?
To fix CVE-2026-15214, update the Subscriptions for WooCommerce plugin to version 2.0.1 or later.
Who is affected by CVE-2026-15214?
Anyone using Subscriptions for WooCommerce version prior to 2.0.1 may be at risk from CVE-2026-15214.
What type of vulnerability is CVE-2026-15214?
CVE-2026-15214 is an IDOR vulnerability that allows unauthorized access to subscription details.
What consequences can result from CVE-2026-15214?
CVE-2026-15214 can lead to unauthorized disclosure of sensitive subscription information between customers.