SQL Injection Vulnerability in Premium Packages Plugin for WordPress
CVE-2026-15906

6.5MEDIUM

What is CVE-2026-15906?

The Premium Packages – Sell Digital Products Securely plugin for WordPress has a SQL Injection vulnerability that arises from inadequate input validation on the 'orderby' parameter. This weakness allows authenticated users with admin-level access to inject additional SQL queries into existing ones. Such actions could potentially compromise sensitive information stored within the database, emphasizing the importance of secure coding practices. Users of all versions up to and including 7.0.4 should take immediate measures to patch this vulnerability to safeguard their digital products and sensitive data.

Affected Version(s)

Premium Packages – Sell Digital Products Securely 0 <= 7.0.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.