haitam lazaar / lazaarsec
← Back to CVE Registry
CVE-2026-108208.1high[patched]

Subscriber+ Subscription Cancellation via IDOR

TARGET ECOSYSTEM / VENDORProfilePress
AFFECTED PRODUCTProfilePress (< 4.16.17)
CWE CLASSIFICATIONCWE-639: Insecure Direct Object Reference
PUBLISHED DATE2026-06-06

Summary

ProfilePress (< 4.16.17) does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user (Subscriber+) to cancel other users’ active subscriptions via an Insecure Direct Object Reference (IDOR).

On lifetime plans the victim’s WordPress role is additionally removed, and where a payment gateway is connected the cancellation is propagated to it. Subscription IDs are sequential integers, allowing automated bulk cancellation.