Stored Cross-Site Scripting Vulnerability in Premium Packages Plugin for WordPress
CVE-2026-103478
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-103478?
The Premium Packages β Sell Digital Products Securely plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) via multiple parameters, including 'checkout[billing][phone]', 'state', 'taxid', and 'email'. This issue arises from inadequate input validation and insufficient output encoding, allowing authenticated users with subscriber-level access or higher to inject malicious scripts. When users access a compromised page, these scripts can execute, potentially leading to session hijacking or other malicious activities.
Affected Version(s)
Premium Packages β Sell Digital Products Securely 0 <= 7.2.6