What is CVE-2026-15215?
The Subscriptions for WooCommerce plugin before version 2.0.1 fails to verify user capability before installing a plugin via an AJAX action, allowing Shop Managers to potentially upload malicious plugins. This can lead to complete site takeover. Immediate update to version 2.0.1 or higher is required.
Azərbaycanca: Subscriptions for WooCommerce plaqini 2.0.1 versiyasından əvvəl `shop_manager` roluna malik istifadəçilərə lazımi icazə yoxlaması olmadan plugin quraşdırmağa imkan verən bir zəiflik ehtiva edir. Bu, zərərli bir plugin yüklənərək saytın ələ keçirilməsinə səbəb ola bilər. Dərhal plaqini 2.0.1 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which WordPress user role can exploit the CVE-2026-15215 vulnerability?
Shop Manager users.
To which version should the Subscriptions for WooCommerce plugin be updated to fix this vulnerability?
Version 2.0.1 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.