Stored Cross-Site Scripting Vulnerability in Premium Packages Plugin for WordPress
CVE-2026-103478

6.4MEDIUM

What is CVE-2026-103478?

The Premium Packages – Sell Digital Products Securely plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) via multiple parameters, including 'checkout[billing][phone]', 'state', 'taxid', and 'email'. This issue arises from inadequate input validation and insufficient output encoding, allowing authenticated users with subscriber-level access or higher to inject malicious scripts. When users access a compromised page, these scripts can execute, potentially leading to session hijacking or other malicious activities.

Affected Version(s)

Premium Packages – Sell Digital Products Securely 0 <= 7.2.6

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.