CVE-2026-6798
Received Received - Intake
Unauthorized Access in 2Download Connector for 2DL Hosted Checkout Plugin

Publication date: 2026-06-19

Last updated on: 2026-06-19

Assigner: Wordfence

Description
The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 0.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view arbitrary customers' subscription data including subscription status, product names, order IDs, purchase dates, and expiry dates.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-19
Last Modified
2026-06-19
Generated
2026-06-19
AI Q&A
2026-06-19
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
2download connector to 0.1.5 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The 2Download Connector for 2DL Hosted Checkout plugin for WordPress has a vulnerability in all versions up to and including 0.1.5. This vulnerability arises because the plugin does not properly verify whether a user is authorized to perform certain actions.

As a result, unauthenticated attackers can exploit this flaw to access arbitrary customers' subscription data without permission.

  • Subscription status
  • Product names
  • Order IDs
  • Purchase dates
  • Expiry dates
Impact Analysis

This vulnerability can lead to unauthorized disclosure of sensitive customer subscription information.

Attackers who exploit this flaw can view private data such as subscription status, product details, order identifiers, and purchase or expiry dates without authentication.

Such exposure can harm customer privacy, damage trust, and potentially lead to further exploitation or fraud.

Compliance Impact

This vulnerability allows unauthenticated attackers to access arbitrary customers' subscription data, including subscription status, product names, order IDs, purchase dates, and expiry dates.

Such unauthorized access to personal and transactional data could lead to non-compliance with data protection regulations like GDPR and HIPAA, which require strict controls on access to personal and sensitive information.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6798. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart