WooCommerce Subscriptions
WooCommerce Subscriptions creates and manages recurring subscription products and payments in WooCommerce.
WooCommerce Subscriptions (woocommerce-subscriptions) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 12, 2026; the highest published CVSS base score is 9.8.
woocommerce-subscriptionsCVE-2026-18391: WooCommerce Subscriptions HPOS input permits unauthenticated object injection
WooCommerce Subscriptions from 4.7.0 before the corrected release for the installed branch unserializes unvalidated request input when High-Performance Order Storage is enabled. An unauthenticated attacker can create a PHP object injection payload; the advisory states that a gadget chain in bundled dependencies permits remote code execution. The endpoint or action, request parameter, unserialize call and gadget classes are not disclosed in the public sources.
| Safe version |
|
||
|---|---|---|---|
| Aug 12, 2026 |
CVE-2026-18391
WooCommerce Subscriptions HPOS input permits unauthenticated object injection
WooCommerce Subscriptions from 4.7.0 before the corrected release for the installed branch unserializes unvalidated request input when High-Performance Order Storage is enabled. An unauthenticated attacker can create a PHP object injection payload; the advisory states that a gadget chain in bundled dependencies permits remote code execution. The endpoint or action, request parameter, unserialize call and gadget classes are not disclosed in the public sources.
|
7.9.1, 8.8.2, 9.1.0 |
CVE9.8
NVDPending
|
| Dec 31, 2024 |
CVE-2023-50850
WooCommerce Subscriptions: A security weakness
WooCommerce Subscriptions is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 20, 2023 |
CVE-2023-35914
Woo Subscriptions: A security weakness
Woo Subscriptions is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|