What is CVE-2026-18391?
CVE-2026-18391 allows unauthenticated PHP Object Injection in WooCommerce Subscriptions plugin before 9.1.0 due to missing user input validation before unserialization when HPOS is enabled. Attackers can escalate this to Remote Code Execution via a gadget chain, making immediate plugin update crucial.
Azərbaycanca: CVE-2026-18391 WooCommerce Subscriptions plugin-in 9.1.0 versiyasından əvvəlki versiyalarında HPOS aktiv olduqda istifadəçi girişini düzgün yoxlamır, bu da unauthenticated PHP Object Injection zəifliyinə səbəb olur. Hücumçular gadget chain vasitəsilə Remote Code Execution-a nail ola bilərlər. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Which versions of the WooCommerce Subscriptions plugin are affected by CVE-2026-18391?
All versions before 9.1.0 are affected by this vulnerability.
How can an attacker achieve Remote Code Execution using CVE-2026-18391?
An attacker can use the unauthenticated PHP Object Injection vulnerability to achieve Remote Code Execution via a gadget chain.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.