Critical severity9.8NVD Advisory· Published Aug 12, 2026· Updated Aug 26, 2026
CVE-2026-18391
CVE-2026-18391
Description
The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a gadget chain present in the bundled dependencies.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <9.1.0
Patches
Vulnerability mechanics
References
1News mentions
1- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 10, 2026 to August 16, 2026)Wordfence Blog · Aug 21, 2026