AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-15215

HIGH · CVSS 8.8 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Subscriptions for WooCommerce plugin for WordPress prior to version 2.0.1 is vulnerable due to insufficient verification of user capabilities, allowing users with the Shop Manager role to install and activate arbitrary plugins via a nonce-protected AJAX action. This flaw can lead to remote code execution, potentially compromising the entire WordPress site. WordPress administrators, especially those using the affected plugin, should prioritize updating to the latest version to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15215
Severity
HIGH
CVSS
8.8
EPSS
0.35%
WordPress

Original NVD Description

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution.