SQL Injection Vulnerability in Premium Packages Plugin for WordPress
CVE-2026-12800
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-12800?
The Premium Packages β Sell Digital Products Securely plugin for WordPress is exposed to SQL Injection vulnerabilities through the 'code' parameter in the POST /wp-json/wpdmpp/v1/cart/coupon REST API endpoint. This weakness arises from inadequate escaping of the user-supplied data, allowing the parameter to be directly interpolated into an SQL query within the CouponCodes::find() method without proper sanitization techniques. As a result, unauthenticated attackers can manipulate existing queries, potentially gaining unauthorized access to sensitive data stored in the database.
Affected Version(s)
Premium Packages β Sell Digital Products Securely 0 <= 6.2.0