← WordPress Vulnerabilities
WordPress security by component

WooCommerce Subscriptions

WooCommerce Subscriptions creates and manages recurring subscription products and payments in WooCommerce.

WooCommerce Subscriptions (woocommerce-subscriptions) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 12, 2026; the highest published CVSS base score is 9.8.

Plugin slug: woocommerce-subscriptions

CVE-2026-18391: WooCommerce Subscriptions HPOS input permits unauthenticated object injection

WooCommerce Subscriptions from 4.7.0 before the corrected release for the installed branch unserializes unvalidated request input when High-Performance Order Storage is enabled. An unauthenticated attacker can create a PHP object injection payload; the advisory states that a gadget chain in bundled dependencies permits remote code execution. The endpoint or action, request parameter, unserialize call and gadget classes are not disclosed in the public sources.

PublishedAug 12, 2026
Known safe version7.9.1, 8.8.2, 9.1.0
Published vulnerabilities for woocommerce-subscriptions
Safe version
Aug 12, 2026 CVE-2026-18391
WooCommerce Subscriptions HPOS input permits unauthenticated object injection
WooCommerce Subscriptions from 4.7.0 before the corrected release for the installed branch unserializes unvalidated request input when High-Performance Order Storage is enabled. An unauthenticated attacker can create a PHP object injection payload; the advisory states that a gadget chain in bundled dependencies permits remote code execution. The endpoint or action, request parameter, unserialize call and gadget classes are not disclosed in the public sources.
7.9.1, 8.8.2, 9.1.0
CVE9.8
NVDPending
Dec 31, 2024 CVE-2023-50850
WooCommerce Subscriptions: A security weakness
WooCommerce Subscriptions is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Dec 20, 2023 CVE-2023-35914
Woo Subscriptions: A security weakness
Woo Subscriptions is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5