---
id: CVE-2026-87854
title: >-
  The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not
  correctly validate the shared secret protecting one of its REST endpoints,
  allowing unauthenticated users to retrieve the store's full list of
  subscriptions, includ…
summary: >-
  The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not
  correctly validate the shared secret protecting one of its REST endpoints,
  allowing unauthenticated users to retrieve the store's full list of
  subscriptions, includ…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
product: Subscriptions for WooCommerce
affected:
  - subscriptions_for_woocommerce < 2.0.3
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:16:56.583'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87854'
references:
  - url: 'https://wpscan.com/vulnerability/a47ee557-3036-485a-91ad-af7b84209294/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-17T12:16:11.965951Z'
epss: 0.00345
epssPercentile: 0.25283
ingestedAt: '2026-09-16T06:51:06.255Z'
---

## Overview

The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting one of its REST endpoints, allowing unauthenticated users to retrieve the store's full list of subscriptions, including customer usernames, product names, recurring amounts and payment dates.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
