The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a gadget chain present in the bundled dependencies.
Security readout for executives and security teams
Plain-English summary
A critical flaw in WooCommerce Subscriptions can let an unauthenticated internet user take control of a vulnerable online store. Exposure requires a version earlier than 9.1.0 and High-Performance Order Storage enabled. Successful exploitation could expose customer data, alter transactions, install malicious content, or disrupt commerce.
Executive priority
Prioritize emergency remediation for revenue-generating or customer-data stores. Patch exposed instances immediately and initiate compromise review where vulnerable configurations were internet-accessible. The potential impact includes full site takeover, data theft, transaction manipulation, malware distribution, and operational outage.
Technical view
Unvalidated user input is unserialized when High-Performance Order Storage is enabled, creating PHP object injection. A gadget chain in bundled dependencies can escalate the flaw to remote code execution without authentication or user interaction. The supplied CVSS 3.1 score is 9.8, with high confidentiality, integrity, and availability impact.
Likely exposure
Internet-accessible WordPress stores using WooCommerce Subscriptions earlier than 9.1.0 with High-Performance Order Storage enabled are likely exposed. The bundle's structured affected-version entry mentions 4.7.0 with an inconsistent default status, so asset owners should verify versions against vendor guidance.
Exploitation context
The source bundle links a WPScan entry tagged as an exploit and technical description, indicating public exploitation information may exist. However, this CVE is not listed as KEV in the supplied data, and no cited evidence confirms active exploitation. Treat exposed stores as urgent because exploitation requires no authentication.
Researcher notes
The supplied description establishes a conditional PHP object-injection path and dependency gadget chain, but provides limited endpoint and implementation detail. The supplied CWE-434 and CWE-94 classifications do not directly describe unsafe deserialization. The affected-version metadata is internally inconsistent, so researchers should rely on the stated pre-9.1.0 boundary while confirming vendor records.
Mitigation direction
Update WooCommerce Subscriptions to version 9.1.0 or later.
Confirm the installed package is genuine and the upgrade completed successfully.
Restrict public access temporarily if an affected store cannot be updated promptly.
Review current vendor guidance for any additional mitigations or incident-response recommendations.
Preserve relevant logs and backups before investigating suspected compromise.
Validation and detection
Inventory WooCommerce Subscriptions versions across all WordPress stores.
Determine whether High-Performance Order Storage is enabled on each store.
Verify no deployed instance remains below version 9.1.0.
Review web, WordPress, and hosting logs for unexplained unauthenticated requests or code execution.
Check for unexpected files, plugins, administrators, scheduled tasks, or configuration changes.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-434: File access and web shell behavior lookup
File traversal and upload weaknesses can lead teams to review file, web shell, execution, and collection telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Code execution and unsafe deserialization weaknesses often justify reviewing execution behavior and process telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
2Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: yesTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.