CVE-2026-18391
WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a gadget chain present in the bundled dependencies.
| Vendor | unknown |
| Product | woocommerce subscriptions |
| Published | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown woocommerce subscriptions
Be the first to know when new unknown vulnerabilities affecting unknown woocommerce subscriptions are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WooCommerce Subscriptions
4.7.0 < 9.1.0
References
Credits
Vasily Belolapotkov Vlad Olaru WPScan