CVE-2026-1926 | wpswings Subscriptions for WooCommerce Plugin up to 1.9.2 on WordPress GET wps_sfw_admin_cancel_susbcription nonce authorization (EUVD-2026-12764)
A vulnerability labeled as problematic has been found in wpswings Subscriptions for WooCommerce Plugin up to 1.9.2 on WordPress. Impacted is the function wps_sfw_admin_cancel_susbcription of the component GET Handler. Executing a manipulation of the argument nonce can lead to missing authorization.
This vulnerability is handled as CVE-2026-1926. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.