The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the save_meta_boxes() function persisting the _wps_plan_user_role membership plan meta from $_POST without an allowlist that excludes privileged roles — the only validations applied, sanitize_key() and wp_roles()->is_role(), both accept 'administrator' as a valid value, and the UI's disabled attribute on the role dropdown is a client-side-only control trivially bypassed via DevTools or a direct POST request; additionally, because the wps_membership_plan custom post type is registered with capability_type => 'post', any user who can edit posts satisfies the current_user_can('edit_post', $post_id) guard in save_meta_boxes(). This makes it possible for authenticated attackers, with Contributor-level access and above, to escalate their privileges to Administrator by storing 'administrator' as the role granted on membership acquisition, which the Pro companion plugin then applies via add_role() during membership lifecycle events. Successful exploitation requires the Subscriptions for WooCommerce Pro companion plugin to be active, as it is the component that reads the stored _wps_plan_user_role meta via get_post_meta() and calls add_role() to apply the role during membership lifecycle events.
References
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the
save_meta_boxes()function persisting the_wps_plan_user_rolemembership plan meta from$_POSTwithout an allowlist that excludes privileged roles — the only validations applied,sanitize_key()andwp_roles()->is_role(), both accept'administrator'as a valid value, and the UI'sdisabledattribute on the role dropdown is a client-side-only control trivially bypassed via DevTools or a direct POST request; additionally, because thewps_membership_plancustom post type is registered withcapability_type => 'post', any user who can edit posts satisfies thecurrent_user_can('edit_post', $post_id)guard insave_meta_boxes(). This makes it possible for authenticated attackers, with Contributor-level access and above, to escalate their privileges to Administrator by storing'administrator'as the role granted on membership acquisition, which the Pro companion plugin then applies viaadd_role()during membership lifecycle events. Successful exploitation requires the Subscriptions for WooCommerce Pro companion plugin to be active, as it is the component that reads the stored_wps_plan_user_rolemeta viaget_post_meta()and callsadd_role()to apply the role during membership lifecycle events.References