What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Woo Subscriptions.This issue affects Woo Subscriptions: from n/a through 5.1.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Woo Subscriptions.This issue affects Woo Subscriptions: from n/a through 5.1.2.
Explanation of Vulnerability in Simple Terms
Woo Subscriptions versions up to 5.1.2 contain an authorization flaw that allows unauthenticated attackers to read sensitive subscription data over the network. The vulnerability requires no user interaction and exposes confidential information without modifying or disrupting service. Site administrators should update to a version newer than 5.1.2 immediately.
What an attacker can do
Read sensitive subscription data without authentication.
Potential impact on your site
Customer subscription details and related sensitive data are exposed to anyone on the internet.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities