{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/wpswings/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-15397"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Subscriptions for WooCommerce (\u003c= 2.0.0)"],"_cs_severities":["high"],"_cs_tags":["wordpress","plugin","web-application-vulnerability","cve-2026-15397"],"_cs_type":"advisory","_cs_vendors":["wpswings"],"content_html":"\u003cp\u003eThe Subscriptions for WooCommerce plugin for WordPress is affected by a missing authorization vulnerability (CVE-2026-15397) in all versions up to and including 2.0.0. The vulnerability resides within the \u003ccode\u003ewps_sfw_install_plugin_configuration\u003c/code\u003e AJAX handler, which fails to verify the authorization level of the user initiating the request. An attacker with authenticated access at the shop manager level or higher can exploit this handler to force the WordPress environment to install and activate arbitrary plugins from the WordPress.org repository. This capability enables attackers to install malicious plugins, resulting in full remote code execution and complete site compromise. Defenders should prioritize updating the plugin to a patched version once available or restricting access to the identified AJAX endpoint.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker authenticates as a user with shop manager or higher privileges on a WordPress site running the vulnerable plugin.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies the \u003ccode\u003ewps_sfw_install_plugin_configuration\u003c/code\u003e AJAX handler endpoint as the target.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a request to the WordPress admin-ajax.php interface, invoking the vulnerable action.\u003c/li\u003e\n\u003cli\u003eThe request includes parameters specifying the target plugin to be fetched from the WordPress.org repository.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to perform a capability check on the current user before processing the installation request.\u003c/li\u003e\n\u003cli\u003eThe WordPress site automatically downloads and installs the specified plugin from the WordPress repository.\u003c/li\u003e\n\u003cli\u003eThe plugin is activated on the site, granting the attacker the functionality provided by the newly installed plugin.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages the installed plugin to execute arbitrary code, escalate privileges, or exfiltrate data from the server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the installation and activation of any plugin from the WordPress.org repository. In a production e-commerce environment, this leads to full site control, administrative access, customer data exfiltration, or the potential deployment of ransomware or backdoors. The vulnerability affects all users running Subscriptions for WooCommerce 2.0.0 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the \u0026quot;Subscriptions for WooCommerce\u0026quot; plugin to the latest available version provided by wpswings to resolve the authorization flaw.\u003c/li\u003e\n\u003cli\u003eInspect site plugin directories for recently installed or unknown plugins that do not align with known approved deployments.\u003c/li\u003e\n\u003cli\u003eAudit user accounts with \u0026quot;Shop Manager\u0026quot; privileges and remove any unauthorized or unnecessary access.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to monitor for suspicious AJAX requests directed toward the plugin's configuration handlers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T13:40:43Z","date_published":"2026-07-30T13:40:43Z","id":"https://feed.craftedsignal.io/briefs/2026-07-subscriptions-woocommerce-auth-bypass/","summary":"An authorization flaw in the Subscriptions for WooCommerce WordPress plugin allows authenticated users with shop manager privileges to remotely install and activate arbitrary plugins.","title":"Authorization Bypass in Subscriptions for WooCommerce Plugin","url":"https://feed.craftedsignal.io/briefs/2026-07-subscriptions-woocommerce-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Wpswings","version":"https://jsonfeed.org/version/1.1"}