Subscriptions for WooCommerce <= 2.0.0 - Authenticated (Contributor+) Privilege Escalation via '_wps_plan_user_role' Membership Plan Meta
Strategic Overview
- Status
- Patched in 2.0.1
- Affected Plugin
- Subscriptions for WooCommerce
- Affected Version
<= 2.0.0- CVSS
- 8.8High
- Weakness type
- CWE-269 · Improper Privilege Management
- CVE
CVE-2026-15414
At a glance
CVE-2026-15414 is a high-severity Improper Privilege Management vulnerability in the Subscriptions for WooCommerce WordPress plugin, affecting versions <= 2.0.0. It carries a CVSS score of 8.8 (reachable over the network; low attack complexity; high confidentiality, integrity, availability impact). Exploitation requires an authenticated account at Contributor level or above. The issue is fixed in version 2.0.1; sites on affected versions should update now. Disclosed July 2026, reported by Wordfence PRISM.
Vulnerability Overview
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged roles — the only validations applied, `sanitize_key()` and `wp_roles()->is_role()`, both accept `'administrator'` as a valid value, and the UI's `disabled` attribute on the role dropdown is a client-side-only control trivially bypassed via DevTools or a direct POST request; additionally, because the `wps_membership_plan` custom post type is registered with `capability_type => 'post'`, any user who can edit posts satisfies the `current_user_can('edit_post', $post_id)` guard in `save_meta_boxes()`. This makes it possible for authenticated attackers, with Contributor-level access and above, to escalate their privileges to Administrator by storing `'administrator'` as the role granted on membership acquisition, which the Pro companion plugin then applies via `add_role()` during membership lifecycle events. Successful exploitation requires the Subscriptions for WooCommerce Pro companion plugin to be active, as it is the component that reads the stored `_wps_plan_user_role` meta via `get_post_meta()` and calls `add_role()` to apply the role during membership lifecycle events.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no interaction from a victim user. A successful exploit has high impact on confidentiality, integrity, availability — full site compromise territory.
CWE-269: Improper Privilege Management
Subscriptions for WooCommerce <= 2.0.0 carries this weakness at administrator, and reaching it takes an account at Contributor level or above. Improper privilege management means the code lets an account end up with capabilities its role should not have.
It converts a low-privileged account into an administrative one, which makes every other restriction on the site irrelevant. For Subscriptions for WooCommerce the fix is 2.0.1: builds <= 2.0.0 are affected, anything from 2.0.1 onward is not.
Remediation
Update to version 2.0.1, or a newer patched version
How does WordSec protect against this?
Because it turns on account access, WordSec's login security is the relevant layer: role-based two-factor, captcha and brute-force limits raise the cost of getting the account this needs. None of that substitutes for the fix: Subscriptions for WooCommerce 2.0.1 closes this, and updating the plugin is the step that ends it.
- Login Security
- Alerts
External References
Related records
Other vulnerabilities in Subscriptions for WooCommerce
- 7.2CVE-2026-15397: Subscriptions… Authenticated (Shop Manager+)
CVE-2026-15397 - 5.3CVE-2026-15211: Subscriptions… Payment Verification Bypass
CVE-2026-15211 - 5.3CVE-2026-56061: Subscriptions for WooCommerce Missing Authorization
CVE-2026-56061 - 5.3CVE-2026-1926: Subscriptions… Unauthenticated Arbitrary Subscription
CVE-2026-1926 - 5.3CVE-2026-24372: Subscriptions for WooCommerce Missing Authorization
CVE-2026-24372 - 4.3CVE-2026-15214: Subscriptions for WooCommerce IDOR
CVE-2026-15214
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C