Home

Description

Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.14.0.

PUBLISHED Reserved 2026-01-23 | Published 2026-05-25 | Updated 2026-05-26 | Assigner Patchstack




MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-862 Missing Authorization

Product status

Default status
unaffected

Any version
affected

Credits

Legion Hunter | Patchstack Bug Bounty program finder

References

patchstack.com/...ken-access-control-vulnerability?_s_id=cve vdb-entry

cve.org (CVE-2026-24527)

nvd.nist.gov (CVE-2026-24527)

Download JSON