← Back to CVE Registry
CVE-2026-108208.1high[patched]
Subscriber+ Subscription Cancellation via IDOR
TARGET ECOSYSTEM / VENDORProfilePress
AFFECTED PRODUCTProfilePress (< 4.16.17)
CWE CLASSIFICATIONCWE-639: Insecure Direct Object Reference
PUBLISHED DATE2026-06-06
ADVISORY / CNAWPScan Advisory (CNA) ↗
Summary
ProfilePress (< 4.16.17) does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user (Subscriber+) to cancel other users’ active subscriptions via an Insecure Direct Object Reference (IDOR).
On lifetime plans the victim’s WordPress role is additionally removed, and where a payment gateway is connected the cancellation is propagated to it. Subscription IDs are sequential integers, allowing automated bulk cancellation.