WooCommerce Subscriptions 9.1.0 Security Update Checklist
August 7, 2026
WooCommerce has released a security update for WooCommerce Subscriptions. If the extension is installed, update it to version 9.1.0 or later, then confirm that subscriptions, renewals, and authorized store access still behave normally.

The vendor says the update resolves several security issues identified during an internal review. Treat every production, staging, and publicly reachable copy as part of the same maintenance task. A plugin that is current on the main store can still leave risk behind on an overlooked copy.
Confirm which sites use WooCommerce Subscriptions
Start with a short inventory of stores and environments that use the extension. Note whether each site has active recurring products, scheduled renewals, payment integrations, or an upcoming billing run. Keep the change window focused: do not combine this update with a theme redesign, payment migration, or unrelated plugin cleanup.
Install the security update
- Open the WordPress dashboard for each affected site.
- Check the installed WooCommerce Subscriptions version.
- Apply the vendor update and confirm the installed version is 9.1.0 or later.
- If the update is not offered, verify the store’s WooCommerce.com connection and active license, then use the vendor’s supported update path.
For a broader maintenance sequence, use our WordPress plugin, theme, and core update guide. Plan recovery according to the store’s own hosting and change-control policy rather than creating an untested archive during an urgent maintenance window.
Verify subscriptions after the update
Use a controlled test that matches the store’s normal workflow. Confirm that a customer can reach subscription-related account pages, that an authorized staff member can manage subscriptions, and that a test checkout or renewal behaves as expected. Check the payment method and renewal schedule that matter most to the business without exposing customer records in tickets or screenshots.
Review the store’s next scheduled renewal with the team responsible for orders or support. If something does not look right, pause unrelated changes, use the documented recovery path, and contact WooCommerce support with a concise account of the version change and the observed business impact.
Keep the security work separate from payment and recovery changes
This advisory is separate from the current Stripe for WooCommerce security update checklist. Stores that use both extensions should verify each one against its own vendor guidance. For planned recovery work, see our guides to backing up WooCommerce without losing orders and restoring WooCommerce without losing orders.
Official source
WooCommerce published the WooCommerce Subscriptions security update on August 5, 2026. Follow the vendor advisory for the current supported update path and contact route. More practical maintenance help is available in our WooCommerce hub and WordPress support hub.

