๐Ÿ” CVE Alert

CVE-2026-19711

UNKNOWN 0.0

Premium Packages โ€“ Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount Withdrawal Request

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.

Vendor unknown
Product premium packages
Published Aug 16, 2026
Stay Ahead of the Next One

Get instant alerts for unknown premium packages

Be the first to know when new unknown vulnerabilities affecting unknown premium packages are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Premium Packages
0 < 7.0.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/ba209669-49bb-40f0-976d-7b77fa0a3c85/

Credits

Farid Narimanov WPScan