Authentication Bypass in Premium Packages Plugin for WordPress
CVE-2026-15348
6.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 July 2026
What is CVE-2026-15348?
The Premium Packages β Sell Digital Products Securely plugin for WordPress contains a significant security flaw that allows unauthenticated attackers to bypass authentication for any non-administrator WordPress user. This vulnerability originates from the 'download()' function, which improperly processes the 'wpdmppdl' parameter without adequate validation, exposing users' accounts to unauthorized access. Attackers can exploit this flaw to gain session-level access as legitimate users, posing a serious risk to account integrity and data security.
Affected Version(s)
Premium Packages β Sell Digital Products Securely 0 <= 7.0.4