CVE-2026-15211 MEDIUM

CVE-2026-15211: Subscriptions for WooCommerce < 2.0.1 - Payment Bypass via Attacker-Supplied PayPal Capture Token

Vendor Unknown
Product Subscriptions for WooCommerce
Published August 7, 2026
Last update August 7, 2026

CVSS base score

5.9/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed on the WooCommerce order-received flow: it captures a client-supplied token and marks the order paid whenever the capture status is COMPLETED, without comparing the captured amount to the order total. This allows an attacker (unauthenticated where guest checkout is enabled) to substitute an approved, uncaptured PayPal order token and have an expensive order marked paid without paying its price.

Explanation of Vulnerability in Simple Terms

02Summary

Subscriptions for WooCommerce versions before 2.0.1 contain a vulnerability that allows an attacker to modify data or functionality without authentication. The attack requires specific network conditions to succeed. No confidential information is exposed, but the integrity of subscription data or site behavior can be compromised.

What an attacker can do

03Attacker Capabilities

Modify subscription data or site functionality without logging in.

Potential impact on your site

04Site Impact

Subscription records or WooCommerce settings could be altered by unauthorized parties.

Conditions required to exploit

05Prerequisites

Network access; specific conditions must be met to exploit (high attack complexity).

Key dates

06Disclosure timeline

August 7, 2026 CVE published
August 7, 2026 Record updated