CVE-2026-15397 | wpswings Subscriptions for WooCommerce Plugin up to 2.0.0 on WordPress AJAX wps_sfw_install_plugin_configuration improper authorization (EUVD-2026-51089)

SecurityVulns

A vulnerability classified as problematic was found in wpswings Subscriptions for WooCommerce Plugin up to 2.0.0 on WordPress. Affected is the function wps_sfw_install_plugin_configuration of the component AJAX Handler. Executing a manipulation can lead to improper authorization.

This vulnerability is registered as CVE-2026-15397. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More