What is CVE-2026-15414?
The Subscriptions for WooCommerce plugin for WordPress up to version 2.0.0 contains a Privilege Escalation vulnerability due to the `save_meta_boxes()` function saving the `_wps_plan_user_role` membership plan meta from POST data without an allowlist check. This could allow authenticated users to assign higher-level roles to themselves. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: WordPress üçün Subscriptions for WooCommerce plugin-in 2.0.0 versiyasına qədər olan versiyalarında `save_meta_boxes()` funksiyası `_wps_plan_user_role` membership plan metasını POST sorğusundan allowlist yoxlaması olmadan saxladığı üçün imtiyaz yüksəltmə (Privilege Escalation) boşluğu mövcuddur. Bu, autentifikasiya olunmuş istifadəçilərə daha yüksək səviyyəli rol təyin etməyə imkan verə bilər. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ1
What is the impact of CVE-2026-15414?
Authenticated users can exploit the `save_meta_boxes()` function in Subscriptions for WooCommerce to manipulate the `_wps_plan_user_role` meta, allowing them to assign higher-level roles to themselves.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.