CRITICAL 9.8 CVE-2026-73364 Published 19 Aug 2026

WordPress Flexible Subscriptions PHP Object Injection

Worried this affects one of your servers?

WordPress plugin Flexible Subscriptions versions 1.8.1 and earlier are affected by a PHP Object Injection vulnerability.

This flaw allows attackers to inject malicious PHP objects, potentially leading to remote code execution.

Reference: CVE-2026-73364 on NVD

← Back to Security News