CVE-2026-87854
N/A
N/A
Summary
The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting one of its REST endpoints, allowing unauthenticated users to retrieve the store's full list of subscriptions, including customer usernames, product names, recurring amounts and payment dates.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Subscriptions for WooCommerce | 0 < 2.0.3 | affected |
Weaknesses
- CWE-200 Information Exposure
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.