WordPress Plugin Vulnerabilities

WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection

Description

The plugin does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a gadget chain present in the bundled dependencies.

Proof of Concept

Affects Plugins

References

Classification

Type
RCE
OWASP top 10
CWE

Miscellaneous

Original Researcher
Vasily Belolapotkov, Vlad Olaru
Verified
Yes

Timeline

Publicly Published
2026-08-10 (about 2 days ago)
Added
2026-08-10 (about 1 day ago)
Last Updated
2026-08-11 (about 8 hours ago)

Other