PT-2026-71025 · WordPress · Woocommerce Subscriptions

·

CVE-2026-18391

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WooCommerce Subscriptions versions prior to 9.1.0
Description Insufficient validation of user input before unserialization occurs on stores with High-Performance Order Storage enabled. This leads to a PHP Object Injection, which unauthenticated users can escalate to Remote Code Execution (RCE) by utilizing a gadget chain—a sequence of existing code fragments—found within the bundled dependencies.
Recommendations Update WooCommerce Subscriptions to version 9.1.0 or later.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18391

Affected Products

Woocommerce Subscriptions