๐Ÿ” CVE Alert

CVE-2026-19711

MEDIUM 6.5

Premium Packages โ€“ Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount Withdrawal Request

CVSS Score
6.5
EPSS Score
0.1%
EPSS Percentile
4th

The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.

Vendor unknown
Product premium packages
Published Aug 16, 2026
Last Updated Aug 17, 2026
Stay Ahead of the Next One

Get instant alerts for unknown premium packages

Be the first to know when new medium vulnerabilities affecting unknown premium packages are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Premium Packages
0 < 7.0.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/ba209669-49bb-40f0-976d-7b77fa0a3c85/

Credits

Farid Narimanov WPScan