CVE-2019-18834: Woocommerce Subscriptions

Medium severity, CVSS 6.1. EPSS: 1.6% chance of exploitation in the next 30 days.

Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Billing Details are mishandled in WCS_Admin_Post_Types in class-wcs-admin-post-types.php.

Affected products

  • Woocommerce Subscriptions: before 2.6.3 (fixed in 2.6.3)

Published 2020-07-23. Last modified 2026-06-17.