CVE-2026-18391

9.8

WooCommerce · Subscriptions

The WooCommerce Subscriptions plugin is vulnerable to PHP Object Injection due to insecure unserialization of user input, enabling unauthenticated remote code execution.

Executive summary

An unauthenticated remote code execution vulnerability in the WooCommerce Subscriptions plugin poses a critical risk to store integrity and server security.

Vulnerability

The plugin fails to validate user input before performing deserialization operations when High-Performance Order Storage is enabled. An unauthenticated attacker can exploit this to trigger a PHP Object Injection, leveraging existing gadget chains to achieve remote code execution.

Business impact

With a CVSS score of 9.8, this vulnerability allows an attacker to gain full control over the affected WordPress site. This could result in complete data theft, site defacement, the installation of backdoors, or the redirection of customer traffic, leading to significant financial and reputational damage.

Remediation

Immediate Action: Update the WooCommerce Subscriptions plugin to version 9.1.0 or later immediately.

Proactive Monitoring: Monitor server access logs for suspicious POST requests and scan the file system for newly created or unauthorized PHP files.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block serialized PHP objects in incoming HTTP requests.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This is an extremely severe vulnerability that requires immediate attention. Organizations running WooCommerce Subscriptions should verify their current version and patch to 9.1.0 without delay to prevent potential compromise of their e-commerce infrastructure.

More WooCommerce CVEs