WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Subscriptions for WooCommerce

Create WooCommerce subscriptions with recurring payments, Subscription Box features, and membership plans with flexible access rules to grow recurring …

8Reported vulnerabilities
8.8Highest CVSS score
2.0.1Latest version
10,000+Active installs

What to do now

Update Subscriptions for WooCommerce to 2.0.1 or later. 8 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 29, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2026-15414 High 8.8 0.3% 0 to 2.0.0 (inclusive) 2.0.1 August 1, 2026
CVE-2026-15397 High 7.2 0.3% 0 to 2.0.0 (inclusive) 2.0.1 July 30, 2026
CVE-2026-15211 Medium 5.9 0.1% 0 up to (but not including) 2.0.1 2.0.1 August 7, 2026
CVE-2026-56061 Medium 5.3 0.3% 1.9.5 and earlier 1.9.6 June 25, 2026
CVE-2026-1926 Medium 5.3 0.3% 0 to 1.9.2 (inclusive) 1.9.3 March 18, 2026
CVE-2026-24372 Medium 5.3 0.5% 1.8.10 and earlier 1.9.0 March 13, 2026
CVE-2026-15215 Medium 4.7 0.4% 2.0.0 and earlier 2.0.1 August 3, 2026
CVE-2026-15214 Medium 4.3 0.2% 2.0.0 and earlier 2.0.1 August 3, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.