CVE-2026-18391

The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a gadget chain present in the bundled dependencies.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-12 06:20

Updated : 2026-08-26 16:30


NVD link : CVE-2026-18391

Mitre link : CVE-2026-18391

CVE.ORG link : CVE-2026-18391


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type