A vulnerability classified as problematic was found in wpswings Subscriptions for WooCommerce Plugin up to 2.0.0 on WordPress. Affected is the function
wps_sfw_install_plugin_configuration of the component AJAX Handler. Executing a manipulation can lead to improper authorization.
This vulnerability is registered as CVE-2026-15397. It is possible to launch the attack remotely. No exploit is available.