What is CVE-2026-73364?
CVE-2026-73364 is a PHP Object Injection vulnerability in the "Flexible Subscriptions" plugin, affecting versions 1.8.1 and earlier. It allows an attacker to inject malicious data that could potentially lead to arbitrary code execution. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-73364 "Flexible Subscriptions" plugininin 1.8.1 və daha əvvəlki versiyalarında müştəri tərəfindən PHP obyekt injeksiyası zəifliyidir. Bu, təcavüzkara potensial olaraq ixtiyari kod icrasına səbəb ola biləcək zərərli məlumat ötürülməsinə imkan verir. Pluginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Which plugin is affected by CVE-2026-73364?
CVE-2026-73364 affects the "Flexible Subscriptions" plugin.
What is the potential impact of CVE-2026-73364?
This PHP Object Injection vulnerability allows an attacker to inject malicious data that could potentially lead to arbitrary code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.