Stored Cross-Site Scripting Vulnerability in Premium Packages Plugin for WordPress
CVE-2026-93654

7.2HIGH

What is CVE-2026-93654?

The Premium Packages – Sell Digital Products Securely plugin for WordPress is exposed to a Stored Cross-Site Scripting (XSS) vulnerability through the 'cart_items[][product_name]' parameter in versions up to and including 7.2.1. The flaw arises from inadequate input sanitization and output escaping techniques. This vulnerability allows unauthenticated attackers to inject malicious web scripts, which could be executed in the browsers of users visiting affected pages. The insecure configuration of the checkout REST route permits unauthorized access, compounding the risk by enabling attackers to persist the injected payloads. Consequently, any logged-in user accessing the compromised invoice could inadvertently execute the malicious code.

Affected Version(s)

Premium Packages – Sell Digital Products Securely 0 <= 7.2.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Coopernicus
.