Known Vulnerabilities for Subscriptions by Woocommerce
Listed below are 1 of the newest known vulnerabilities associated with "Subscriptions" by "Woocommerce".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-67975 json | Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new stream... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-65696 json | Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription ... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65319 json | Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attacke... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-63758 json | SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated... | Not Provided | 2026-07-20 | 2026-07-20 |
| CVE-2026-63753 json | SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. Attacke... | Not Provided | 2026-07-20 | 2026-07-23 |
| CVE-2026-63749 json | SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permission ... | Not Provided | 2026-07-20 | 2026-07-20 |
| CVE-2026-59539 json | Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions. | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-58252 json | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, an... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-58225 json | SQL Injection vulnerability in elixir-ecto postgrex allows an attacker who can influence a LISTEN channel name to inject SQL ... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-57364 json | Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donation... | Not Provided | 2026-07-13 | 2026-07-13 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Woocommerce | Subscriptions | 2.6.3 | |||
| Application | Woocommerce | Subscriptions | 2.6.2 | |||
| Application | Woocommerce | Subscriptions | 2.6.1 | |||
| Application | Woocommerce | Subscriptions | 2.6.0 | |||
| Application | Woocommerce | Subscriptions | 2.5.7 | |||
| Application | Woocommerce | Subscriptions | 2.5.6 | |||
| Application | Woocommerce | Subscriptions | 2.5.5 | |||
| Application | Woocommerce | Subscriptions | 2.5.4 | |||
| Application | Woocommerce | Subscriptions | 2.5.3 | |||
| Application | Woocommerce | Subscriptions | 2.5.2 | |||
| Application | Woocommerce | Subscriptions | 2.5.1 | |||
| Application | Woocommerce | Subscriptions | 2.5.0 | |||
| Application | Woocommerce | Subscriptions | 2.4.7 | |||
| Application | Woocommerce | Subscriptions | 2.4.6 | |||
| Application | Woocommerce | Subscriptions | 2.4.5 | |||
| Application | Woocommerce | Subscriptions | 2.4.4 | |||
| Application | Woocommerce | Subscriptions | 2.4.3 | |||
| Application | Woocommerce | Subscriptions | 2.4.2 | |||
| Application | Woocommerce | Subscriptions | 2.4.1 | |||
| Application | Woocommerce | Subscriptions | 2.4.0 |