WooCommerce Subscriptions is vulnerable to Remote Code Execution (RCE)
98
Critical Risk
On stores with High-Performance Order Storage enabled, WooCommerce Subscriptions unserializes attacker-controlled input without validation. An unauthenticated attacker can trigger PHP object injection and escalate to remote code execution through a gadget chain in the plugin's bundled dependencies. The fix validates that input before unserialization so crafted payloads cannot instantiate attacker-controlled objects.
You are affected if you are using a version that falls within the vulnerable range and have High-Performance Order Storage enabled.
WooCommerce Subscriptions is vulnerable to Remote Code Execution (RCE) in versions 4.7.0 - 9.0.0.
Upgrade the WooCommerce Subscriptions library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant