CRITICAL
9.8 CVE-2026-73364 Published 19 Aug 2026
WordPress Flexible Subscriptions PHP Object Injection
Worried this affects one of your servers?
WordPress plugin Flexible Subscriptions versions 1.8.1 and earlier are affected by a PHP Object Injection vulnerability.
This flaw allows attackers to inject malicious PHP objects, potentially leading to remote code execution.
Reference: CVE-2026-73364 on NVD
← Back to Security News