WordPress Plugin Vulnerabilities

Subscriptions for WooCommerce < 2.0.3 - Unauthenticated Subscription Data Disclosure via REST API Secret Key Bypass

Description

The plugin does not correctly validate the shared secret protecting one of its REST endpoints, allowing unauthenticated users to retrieve the store's full list of subscriptions, including customer usernames, product names, recurring amounts and payment dates.

Proof of Concept

Affects Plugins

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Karthik Ramakrishnan
Submitter
Karthik Ramakrishnan
Verified
Yes

Timeline

Publicly Published
2026-09-14 (about 3 days ago)
Added
2026-09-14 (about 2 days ago)
Last Updated
2026-09-14 (about 2 days ago)

Other