Stored Cross-Site Scripting Vulnerability in Premium Packages Plugin for WordPress
CVE-2026-93654
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-93654?
The Premium Packages β Sell Digital Products Securely plugin for WordPress is exposed to a Stored Cross-Site Scripting (XSS) vulnerability through the 'cart_items[][product_name]' parameter in versions up to and including 7.2.1. The flaw arises from inadequate input sanitization and output escaping techniques. This vulnerability allows unauthenticated attackers to inject malicious web scripts, which could be executed in the browsers of users visiting affected pages. The insecure configuration of the checkout REST route permits unauthorized access, compounding the risk by enabling attackers to persist the injected payloads. Consequently, any logged-in user accessing the compromised invoice could inadvertently execute the malicious code.
Affected Version(s)
Premium Packages β Sell Digital Products Securely 0 <= 7.2.1