ConicPlex

Start Your Project

A credit card being tapped against a contactless payment terminal on a retail counter

On this Page

WooCommerce Subscriptions Patches a Critical Unauthenticated RCE (CVE-2026-18391)

WooCommerce Subscriptions 9.1.0 fixes CVE-2026-18391, a CVSS 9.8 unauthenticated remote code execution flaw affecting stores with High-Performance Order Storage enabled. Here is what happened and what to do about it.

Husen Memon

August 15, 2026

WooCommerce shipped version 9.1.0 of its Subscriptions plugin on August 5, patching a critical vulnerability that let an unauthenticated attacker execute arbitrary code on a store’s server. The issue was assigned CVE-2026-18391 and carries a CVSS score of 9.8, about as bad as this rating gets. If you run WooCommerce Subscriptions and haven’t updated in the last week and a half, this is worth stopping to check right now.

What the vulnerability actually is

The bug lives in how the plugin handles unserialization of user-supplied data, but only on stores that have High-Performance Order Storage (HPOS) turned on. Without validating that input first, an attacker could trigger a PHP Object Injection and chain it through a gadget already present in the plugin’s bundled dependencies to reach full remote code execution, no login required. NVD lists the affected range as version 4.7.0 through 9.0.x, so this has been sitting in the plugin for a long time before anyone caught it.

WooCommerce’s own security advisory is more general than the CVE record, describing “several security vulnerabilities” with the worst allowing “an unauthorized user to assume site control.” That lines up with what NVD and WPScan’s vulnerability database describe for CVE-2026-18391 specifically. The company says the flaw was found through an internal security review, not by watching it get exploited, and states it has no evidence of any store being compromised or any customer data accessed.

Who’s actually exposed

Two things have to both be true for a store to be at risk: WooCommerce Subscriptions below 9.1.0, and HPOS enabled. HPOS has been WooCommerce’s recommended default for new stores for a while now, so plenty of merchants running recurring billing or membership products through Subscriptions will meet both conditions without having thought about it. If you’re not sure whether HPOS is on, it’s under WooCommerce > Settings > Advanced > Features.

This isn’t the only WooCommerce-adjacent plugin patched this month. WooCommerce Social Login and a Stripe extension both had their own fixes land in the same window, which is a decent sign that the plugin family got a closer look recently rather than one isolated bug.

What to do about it

  • Update WooCommerce Subscriptions to 9.1.0 or later immediately, before anything else on this list.
  • If the site has been running an older version with HPOS on for a while, don’t assume the “no evidence of compromise” line covers you. Check admin user accounts for anything unfamiliar, look for unexpected files in the uploads directory, and review recent order and file activity.
  • Rotate API keys and reset admin passwords if anything looks even slightly off. Unauthenticated RCE means an attacker who found this before the patch didn’t need your credentials to get in.

For stores where nobody’s been keeping close tabs on plugin versions across dozens of installs, this is the kind of gap a WooCommerce Development audit is built to catch before it turns into an incident report instead of a changelog entry.

Sources

Husen Memon is a co-founder of ConicPlex, a web development agency specializing in WordPress, Webflow, and custom software builds. Over more than 9 years and 200+ client projects, he has worked across everything from plugin development to full platform migrations, with a focus on building sites and tools that hold up under real day-to-day use, not just in a demo. He writes here about the technical decisions and tradeoffs that come up in that work.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

News & Updates

A laptop glowing with WordPress blue light on a dark desk at night, surrounded by several identical old brass keys half hidden under a notebook, symbolizing a backdoor that hides duplicate copies of itself.

WordPress Backdoor SC Survives Cleanup by Hiding in Files, Database, and Memory

Sucuri documented a self-healing WordPress backdoor called SC that rebuilds itself from eight hiding spots, including shared memory, after a…

Aftab Memon

October 3, 2026

News & Updates

A laptop glowing with a soft magenta light next to an ID keycard on a wooden desk, symbolizing a WordPress admin access vulnerability

Elementor Patches a Critical CSRF Flaw That Could Hand Attackers Admin Access (CVE-2026-62062)

A CSRF flaw in Elementor 4.3.0 and 4.3.1 (CVE-2026-62062, CVSS 8.8) let attackers create admin accounts with one click. Patched…

Aftab Memon

October 2, 2026

Plugins

Stack of to-do list task cards with checkboxes in front of a faded kanban board, illustrating WordPress dashboard to-do list and task management plugins

How to Add a To-Do List to Your WordPress Dashboard (4 Plugins Compared)

Compare four real WordPress plugins for a dashboard to-do list or task board, from a simple single-person widget to full…

Husen Memon

October 2, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant