CVE-2026-18391

CVE-2026-18391: WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection

Vendor Unknown
Product WooCommerce Subscriptions
Published August 12, 2026
Last update August 12, 2026

CVSS base score

What the vulnerability does

01Description

The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a gadget chain present in the bundled dependencies.

Key dates

02Disclosure timeline

August 12, 2026 CVE published
August 12, 2026 Record updated