WordPress Plugin Vulnerabilities

Subscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Installation

Description

The plugin does not verify the user's capability before installing and activating a plugin from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack plugin-management capabilities) to install and activate arbitrary plugins, resulting in remote code execution.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Khaled Alenazi (Nxploited)
Submitter
Khaled Alenazi (Nxploited)
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-08-03 (about 25 days ago)
Added
2026-08-03 (about 24 days ago)
Last Updated
2026-08-03 (about 24 days ago)

Other