Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-15414: CWE-269 Improper Privilege Management in wpswings Subscriptions for WooCommerce

0
High
VulnerabilityCVE-2026-15414cvecve-2026-15414cwe-269
Published: 08/01/2026 (08/01/2026, 01:29:56 UTC)
Source: CVE Database V5
Vendor/Project: wpswings
Product: Subscriptions for WooCommerce

Description

Subscriptions for WooCommerce plugin for WordPress versions up to and including 2.0.0 contains a privilege escalation vulnerability. The vulnerability arises from improper validation in the save_meta_boxes() function, allowing authenticated users with Contributor-level access or higher to escalate their privileges to Administrator. This occurs because the plugin accepts the 'administrator' role from user input without proper allowlisting and relies on client-side controls that can be bypassed. Exploitation requires the Pro companion plugin to be active, which applies the elevated role during membership lifecycle events.

CVSS v3.1

Score 8.8high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected software

Affected versions
<=2.0.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/01/2026, 02:47:50 UTC

Technical Analysis

CVE-2026-15414 is a privilege escalation vulnerability in the Subscriptions for WooCommerce WordPress plugin (<=2.0.0). The save_meta_boxes() function persists the _wps_plan_user_role meta from POST data without restricting privileged roles. The only validations (sanitize_key() and wp_roles()->is_role()) accept 'administrator' as valid, and the UI's disabled attribute on the role dropdown is a client-side control easily bypassed. Since the custom post type uses capability_type 'post', any user with edit_post capability (Contributor and above) can trigger save_meta_boxes(). The Pro companion plugin reads this meta and applies the role via add_role(), enabling privilege escalation to Administrator.

Potential Impact

An authenticated user with Contributor-level or higher access can escalate their privileges to Administrator by exploiting this vulnerability. This results in full administrative control over the WordPress site, including the ability to modify content, install plugins, and change site settings. The vulnerability requires the Pro companion plugin to be active to apply the elevated role, making exploitation conditional on this component.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict Contributor-level and higher users from accessing membership plan editing features or disable the Subscriptions for WooCommerce Pro companion plugin if not required. Monitor vendor channels for updates and apply patches promptly once released.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
Wordfence
Date Reserved
2026-07-10T14:30:07.093Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null

Threat ID: 6a6d5b2bbf32cb7a34f84ea0

Added to database: 08/01/2026, 02:34:19 UTC

Last enriched: 08/01/2026, 02:47:50 UTC

Last updated: 08/01/2026, 02:53:40 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses