Intel

AIKIDO-2026-955132

WooCommerce Subscriptions is vulnerable to Remote Code Execution (RCE)

Remote Code Execution (RCE)CVE-2026-18391 Published Aug 13, 2026

98

Critical Risk

This Affects:

PHPWooCommerce Subscriptions
4.7.0 - 9.0.0
Fixed in 9.1.0
Are you affected? Scan for Free

TL;DR

On stores with High-Performance Order Storage enabled, WooCommerce Subscriptions unserializes attacker-controlled input without validation. An unauthenticated attacker can trigger PHP object injection and escalate to remote code execution through a gadget chain in the plugin's bundled dependencies. The fix validates that input before unserialization so crafted payloads cannot instantiate attacker-controlled objects.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and have High-Performance Order Storage enabled.

Background info

WooCommerce Subscriptions is vulnerable to Remote Code Execution (RCE) in versions 4.7.0 - 9.0.0.

How to fix this

Upgrade the WooCommerce Subscriptions library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform