WordPress · Woocommerce Subscriptions · CVE-2026-18391
**Name of the Vulnerable Software and Affected Versions**
WooCommerce Subscriptions versions prior to 9.1.0
**Description**
Insufficient validation of user input before unserialization occurs on stores with High-Performance Order Storage enabled. This leads to a PHP Object Injection, which unauthenticated users can escalate to Remote Code Execution (RCE) by utilizing a gadget chain—a sequence of existing code fragments—found within the bundled dependencies.
**Recommendations**
Update WooCommerce Subscriptions to version 9.1.0 or later.