CVE-2026-19711
Premium Packages โ Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount Withdrawal Request
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.
| Vendor | unknown |
| Product | premium packages |
| Published | Aug 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown premium packages
Be the first to know when new unknown vulnerabilities affecting unknown premium packages are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Premium Packages
0 < 7.0.7
References
Credits
Farid Narimanov WPScan