Intel

AIKIDO-2026-955132

WooCommerce Subscriptions is vulnerable to Remote Code Execution (RCE)

Remote Code Execution (RCE)CVE-2026-18391 Published Aug 13, 2026

98

Critical Risk

This Affects:

PHPWooCommerce Subscriptions
4.7.0 - 9.0.0
Fixed in 9.1.0
Are you affected? Scan for Free

TL;DR

On stores with High-Performance Order Storage enabled, WooCommerce Subscriptions unserializes attacker-controlled input without validation. An unauthenticated attacker can trigger PHP object injection and escalate to remote code execution through a gadget chain in the plugin's bundled dependencies. The fix validates that input before unserialization so crafted payloads cannot instantiate attacker-controlled objects.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and have High-Performance Order Storage enabled.

Background info

WooCommerce Subscriptions is vulnerable to Remote Code Execution (RCE) in versions 4.7.0 - 9.0.0.

How to fix this

Upgrade the WooCommerce Subscriptions library to the patch version.