WordPress PHP Object Injection: 115 unserialize() Calls
On 12 August 2026, an advisory landed for WooCommerce Subscriptions: unauthenticated PHP object injection, escalating to remote code execution, in every version below 9.1.0. The trigger condition is the interesting part — it applies when High-Performance Order Storage is switched on. HPOS is switched on here. So before writing anything about it, I ran the…