CVE-2026-18391 PUBLISHED

WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection

Assigner: WPScan
Reserved: 30.07.2026 Published: 12.08.2026 Updated: 12.08.2026

The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a gadget chain present in the bundled dependencies.

Product Status

Vendor Unknown
Product WooCommerce Subscriptions
Versions Default: unaffected
  • affected from 4.7.0 to 9.1.0 (excl.)

Credits

  • Vasily Belolapotkov finder
  • Vlad Olaru finder
  • WPScan coordinator

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE