Description
The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.
Published: 2026-08-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Premium Packages WordPress plugin before 7.0.7 fails to validate a withdrawal request against the user’s actual earned balance, allowing any authenticated user — including subscribers with no sales — to submit a payout request for an arbitrary amount. The flaw gives the requester financial integrity abuse: they can obtain funds without legitimate sales. This weakness corresponds to CWE‑284 (Improper Authorization). The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of <1% suggests low observable exploitation risk. No KEV listing is issued, yet the financial risk is significant.

Affected Systems

The vulnerability exists in the Premium Packages WordPress plugin for any version prior to 7.0.7. It affects installations that use the plugin for managing digital product sales and withdrawals, regardless of the WordPress site’s admin configuration. Only users who are logged in and have access to the withdrawal request interface are affected; the flaw does not allow unauthenticated users to initiate withdrawals.

Risk and Exploitability

The risk is moderate to high because the flaw allows authenticated users to request arbitrary payouts that an administrator can approve. The CVSS score of 6.5 reflects this moderate severity, while the EPSS <1% indicates low observable exploitation risk but does not diminish the potential impact if a user can get admin approval. The likely attack vector is internal, requiring only WordPress authentication; no network exploitation is needed. This inference is based on the description that the flaw affects authenticated users. The unvalidated balance check removes a critical safeguard, exposing substantial financial loss if abused.

Generated by OpenCVE AI on August 18, 2026 at 02:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Premium Packages plugin to version 7.0.7 or newer, which adds balance validation to withdrawal requests.
  • If an upgrade is not possible immediately, restrict the withdrawal feature to administrators only or disable it for non‑administrator roles until the flaw is fixed.
  • Implement monitoring or logging of withdrawal approvals to detect suspicious payout requests and investigate any anomalies.

Generated by OpenCVE AI on August 18, 2026 at 02:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Mon, 17 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 16 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Sun, 16 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.
Title Premium Packages – Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount Withdrawal Request
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-17T20:25:23.705Z

Reserved: 2026-08-13T10:33:17.336Z

Link: CVE-2026-19711

cve-icon Vulnrichment

Updated: 2026-08-17T20:25:18.711Z

cve-icon NVD

Status : Deferred

Published: 2026-08-16T06:16:52.120

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-19711

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T03:00:09Z

Weaknesses