PHP Object Injection Vulnerability in Flexible Subscriptions by WordPress
CVE-2026-73364
9.8CRITICAL
What is CVE-2026-73364?
A vulnerability has been identified in the Flexible Subscriptions WordPress plugin, allowing for PHP Object Injection in versions 1.8.1 and earlier. This flaw can potentially enable attackers to execute arbitrary code, leading to unauthorized access and manipulation of the system. Users are urged to upgrade to the latest version to mitigate this risk.
Affected Version(s)
Flexible Subscriptions <= 1.8.1