What is CVE-2026-15211?
CVE-2026-15211 is a critical vulnerability in the Subscriptions for WooCommerce WordPress plugin before version 2.0.1. It fails to validate the payment amount and does not bind the PayPal order token to the specific order, allowing an attacker to capture a client-supplied token and mark the order as paid. Users must update the plugin to at least version 2.0.1 immediately.
Azərbaycanca: CVE-2026-15211, Subscriptions for WooCommerce WordPress plugin-nin 2.0.1-dən əvvəlki versiyalarında aşkar olunmuş kritik zəiflikdir. Bu boşluq, ödəniş məbləğini yoxlamadığı və PayPal order token-i sifarişlə düzgün əlaqələndirmədiyi üçün təcavüzkara sifarişi tamamlanmış kimi göstərməyə imkan verir. İstifadəçilər dərhal plugin-i ən azı 2.0.1 versiyasına yeniləməlidir.
Related CVEs
link basis: shared vendors: PayPal, WooCommerce
FAQ2
Which versions of the Subscriptions for WooCommerce plugin are affected by CVE-2026-15211?
This vulnerability affects all versions of the plugin prior to 2.0.1.
What can an attacker achieve by exploiting CVE-2026-15211?
By capturing a client-supplied PayPal order token, an attacker can bypass the payment amount validation and mark the order as paid.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.