CVE-2026-87860: Subscriptions for WooCommerce < 2.0.3 - Subscription Cancellation via CSRF
Published Sep 16, 2026
·Updated
The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make a logged-in customer cancel their own active subscription through a crafted request they are tricked into making.
Event History
Sep 16, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can be affected by this issue?
Logged-in customers with an active subscription can be induced to cancel their own subscription. The affected component is Subscriptions for WooCommerce versions before 2.0.3.
2
What must an attacker do to exploit it?
An attacker must cause a logged-in customer to make a crafted request that triggers subscription cancellation. The issue is caused by the cancellation request not verifying a security token.
3
How can I determine whether my site is affected?
Check the installed Subscriptions for WooCommerce plugin version. Versions before 2.0.3 are affected.