Security Advisory

CVE-2026-87860

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-16 06:00:16
Last updated 2026-09-17 12:32:58
Assigner WPScan
CVSS score 4.3
State PUBLISHED

Description

The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make a logged-in customer cancel their own active subscription through a crafted request they are tricked into making.