CyberRota Analysis
AI-GeneratedThe Subscriptions for WooCommerce plugin for WordPress prior to version 2.0.1 is vulnerable due to insufficient verification of user capabilities, allowing users with the Shop Manager role to install and activate arbitrary plugins via a nonce-protected AJAX action. This flaw can lead to remote code execution, potentially compromising the entire WordPress site. WordPress administrators, especially those using the affected plugin, should prioritize updating to the latest version to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution.