Beveiligingsadvies

CVE-2026-87860

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-16 06:00:16
Laatst bijgewerkt 2026-09-17 12:32:58
Toegewezen door WPScan
CVSS-score 4.3
Status PUBLISHED

Beschrijving

The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make a logged-in customer cancel their own active subscription through a crafted request they are tricked into making.