Known Vulnerabilities for Subscriptions by Woocommerce
Listed below are 1 of the newest known vulnerabilities associated with "Subscriptions" by "Woocommerce".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-77789 json | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the cus... | Not Provided | 2026-08-26 | 2026-08-26 |
| CVE-2026-77066 json | The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.g... | Not Provided | 2026-08-20 | 2026-08-21 |
| CVE-2026-76239 json | Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subscriptions, allowing authen... | Not Provided | 2026-08-19 | 2026-08-21 |
| CVE-2026-74972 json | Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-73364 json | Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. | Not Provided | 2026-08-19 | 2026-08-19 |
| CVE-2026-73079 json | Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.13... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-67975 json | Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new stream... | Not Provided | 2026-08-03 | 2026-08-06 |
| CVE-2026-65696 json | Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription ... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65319 json | Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attacke... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-63758 json | SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated... | Not Provided | 2026-07-20 | 2026-07-20 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Woocommerce | Subscriptions | 2.6.3 | |||
| Application | Woocommerce | Subscriptions | 2.6.2 | |||
| Application | Woocommerce | Subscriptions | 2.6.1 | |||
| Application | Woocommerce | Subscriptions | 2.6.0 | |||
| Application | Woocommerce | Subscriptions | 2.5.7 | |||
| Application | Woocommerce | Subscriptions | 2.5.6 | |||
| Application | Woocommerce | Subscriptions | 2.5.5 | |||
| Application | Woocommerce | Subscriptions | 2.5.4 | |||
| Application | Woocommerce | Subscriptions | 2.5.3 | |||
| Application | Woocommerce | Subscriptions | 2.5.2 | |||
| Application | Woocommerce | Subscriptions | 2.5.1 | |||
| Application | Woocommerce | Subscriptions | 2.5.0 | |||
| Application | Woocommerce | Subscriptions | 2.4.7 | |||
| Application | Woocommerce | Subscriptions | 2.4.6 | |||
| Application | Woocommerce | Subscriptions | 2.4.5 | |||
| Application | Woocommerce | Subscriptions | 2.4.4 | |||
| Application | Woocommerce | Subscriptions | 2.4.3 | |||
| Application | Woocommerce | Subscriptions | 2.4.2 | |||
| Application | Woocommerce | Subscriptions | 2.4.1 | |||
| Application | Woocommerce | Subscriptions | 2.4.0 |