CVE-2026-87860
N/A
N/A
Summary
The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make a logged-in customer cancel their own active subscription through a crafted request they are tricked into making.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Subscriptions for WooCommerce | 0 < 2.0.3 | affected |
Weaknesses
- CWE-862 Missing Authorization
- CWE-352 Cross-Site Request Forgery (CSRF)
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.