Impact
The Premium Packages – Sell Digital Products Securely plugin for WordPress allows a generic SQL injection through the "orderby" parameter because the value is not properly escaped and is directly inserted into an existing SQL query. An attacker who has authenticated admin‑level or higher privileges can append arbitrary SQL commands, enabling the extraction of sensitive data from the database or execution of additional SQL statements. The flaw is classified as CWE‑89 and directly threatens the integrity and confidentiality of the underlying data store.
Affected Systems
Any WordPress site running Premium Packages version 7.0.4 or earlier is affected. The vulnerable product is Codename065’s Premium Packages – Sell Digital Products Securely plugin. All installations of these versions on any WordPress site are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access with admin or higher rights; therefore the attack surface is limited to sites where an attacker has already obtained admin credentials or can compromise an admin account. It is inferred that shared or weak admin privileges might elevate risk, especially if no additional hardening measures are in place.
OpenCVE Enrichment