CVE-2026-18391

WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection

The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a gadget chain present in the bundled dependencies.


We have discovered 12,882 live websites that are affected by CVE-2026-18391.

Run a Free Instant Scan




Affected Software

Product  WooCommerce Subscriptions
Category Wordpress Plugins
Vulnerable Domains12,882 live websites (86% of WooCommerce Subscriptions install base)
Vulnerable Versions
  • from 4.7 through 9.1
Vulnerable Versions Count40 versions ( 40% of all versions)


Common Weakness Enumeration

CWE-94 Improper Control of Generation of Code ('Code Injection')



Details

  • Published - Aug 12, 2026
  • Updated - Aug 12, 2026

Credits

  • Vasily Belolapotkov (finder)
  • Vlad Olaru (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-18391
United States7,077 websites



GB998 websites
Germany685 websites
France422 websites
Australia383 websites
Canada356 websites
Spain329 websites
Netherlands312 websites
Denmark162 websites
South Africa160 websites

Website Distribution by TLD

Number of websites using CVE-2026-18391
.com7,109 websites
.org1,138 websites
.co.uk567 websites
.com.au309 websites
.net279 websites
.de271 websites
.nl253 websites
.ca204 websites
.fr155 websites
.es135 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-18391

Top websites that are affected by CVE-2026-18391. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********************.de Germany*,***
****.net United States*,***
********.com Germany*,***
***********.com Singapore*,***
****.org Hong Kong*,***
********.com United States*,***
*********.com United States*,***
************.com United States*,***
**********.com United States*,***
**********.com United States*,***
See full domain list

FAQ

CVE-2026-18391 is Improper Control of Generation of Code ('Code Injection') in WooCommerce Subscriptions
A total of 12,882 websites have been identified as vulnerable to CVE-2026-18391, based on global website indexing conducted by WebTechSurvey.
The WooCommerce Subscriptions is affected by the CVE-2026-18391 vulnerability.
WooCommerce Subscriptions versions up to 9.1 are vulnerable to CVE-2026-18391.
CVE-2026-18391 is resolved in version 9.1 of WooCommerce Subscriptions.