What the vulnerability does
01Description
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed on the WooCommerce order-received flow: it captures a client-supplied token and marks the order paid whenever the capture status is COMPLETED, without comparing the captured amount to the order total. This allows an attacker (unauthenticated where guest checkout is enabled) to substitute an approved, uncaptured PayPal order token and have an expensive order marked paid without paying its price.
Explanation of Vulnerability in Simple Terms
02Summary
Subscriptions for WooCommerce versions before 2.0.1 contain a vulnerability that allows an attacker to modify data or functionality without authentication. The attack requires specific network conditions to succeed. No confidential information is exposed, but the integrity of subscription data or site behavior can be compromised.
What an attacker can do
03Attacker Capabilities
Modify subscription data or site functionality without logging in.
Potential impact on your site
04Site Impact
Subscription records or WooCommerce settings could be altered by unauthorized parties.
Conditions required to exploit
05Prerequisites
Network access; specific conditions must be met to exploit (high attack complexity).
Key dates
06Disclosure timeline
August 7, 2026
CVE published
August 7, 2026
Record updated