CVE-2026-18391Patch

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a gadget chain present in the bundled dependencies.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-08-12); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-12: 1Mentions · 2026-08-31: 1Mentions · 2026-09-02: 1Patch / Workaround · 2026-08-31: 1Patch / Workaround · 2026-09-02: 1Technical Details · 2026-08-12: 1Technical Details · 2026-08-31: 1Technical Details · 2026-09-02: 108-1208-3109-02
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-121
Disclosure1
2026-08-311
Patch1
2026-09-021
Patch1
Full discourse3 posts
  • Dominik@GronskiDev
    Patch

    W sierpniu 2026 w ekosystemie WooCommerce trzy krytyczne łatki: 5 sierpnia - WooCommerce Subscriptions 9.1.0 (CVE-2026-18391, RCE) 6 sierpnia - Stripe for WooCommerce 10.8.5 (wewnętrzny pentest, brak public CVE) 10 sierpnia - WooCommerce 11.0.1 (17 PR-ów sześć dni po 11.0) 12 sierpnia - WordPress 6.8.8 (maintenance security) Cztery updates w dwa tygodnie. Wszystkie ważne, część krytyczna. Dlatego pakiet SLA za 199-1499 zł/mc dla sklepu WooCommerce nie jest zdzierstwem. To ktoś kto pilnuje żeby te cztery patche zostały odpalone w oknie 24-48h, na stagingu, z backupem, bez zabicia płatności subskrybentów. Alternatywa: robisz to sam w niedzielę wieczorem, jak wiesz jak. Albo dopadnie Cię cyber-atak jakich w PL w 2026 jest rekord (+144% ransomware r/r). Sklep to nie jest zabawka na 12 miesięcy. To jest infrastruktura na dekadę.

    Post summary

    The post lists critical WooCommerce patches, including the CVE‑2026‑18391 RCE, and stresses that timely patching via an SLA service is essential to avoid potential cyber‑attacks.

    0000083
    17 followersView on X
  • Dominik@GronskiDev
    Patch

    Krótko i PSA dla wszystkich którzy prowadzą sklep z subskrypcjami na WooCommerce. 12 sierpnia opublikowany CVE-2026-18391. PHP Object Injection w WooCommerce Subscriptions przy włączonym HPOS. Wektor: nieuwierzytelniony atakujący, ładunek zdalny, wynik RCE na serwerze. Łatka wyszła 5 sierpnia. Wersja bezpieczna: 9.1.0 lub wyżej. Co zrobić dziś: 1. Sprawdź w panelu Wtyczki jaka wersja Subscriptions. 2. Jeśli 9.0.x lub niżej - aktualizuj. 3. Jeśli nie wiesz jak zaktualizować bez ubicia płatności subskrybentów (staging, backup bazy, procedura), napisz. Robię to standardowo w pakiecie SLA. Niektóre CVE można odpuścić na tydzień. Tego nie.

    Post summary

    The message announces CVE‑2026‑18391, a PHP Object Injection leading to RCE in WooCommerce Subscriptions, and advises updating to version 9.1.0 or later to mitigate the issue.

    0000048
    17 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-18391 The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled… https://www.cve.org/CVERecord?id=CVE-2026-18391

    Post summary

    The content is a brief disclosure of a vulnerability in the WooCommerce Subscriptions plugin, outlining the flaw without providing exploit details, patches, or evidence of active exploitation.

    00000911
    57.9K followersView on X

Explore more