Description
Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
Published: 2026-07-23
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WPDM – Premium Packages plugin contains an unauthenticated broken access control flaw in versions up to and including 6.2.0. The vulnerability allows attackers to access functionality that is normally protected, because authentication checks are bypassed.

Affected Systems

The vulnerability affects the Shahjada WPDM – Premium Packages plugin for WordPress, versions up to and including 6.2.0. Any site running those versions is vulnerable; updating to 7.0.0 or later resolves the issue.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity. The EPSS score of <1% reflects a very low current probability of exploitation, and the flaw is not listed in CISA's KEV catalog. The flaw can be reached remotely over the web without any prior authentication, so attackers can potentially exploit it via automated scans or targeted requests. No specific configuration or privileged state is required to launch an attack.

Generated by OpenCVE AI on August 3, 2026 at 22:17 UTC.

Remediation

Vendor Solution

Update the WordPress WPDM – Premium Packages Plugin to the latest available version (at least 7.0.0).


OpenCVE Recommended Actions

  • Update the WPDM – Premium Packages Plugin to version 7.0.0 or later
  • If an immediate update is not possible, block access to plugin URLs such as /wpdm/ or /wpdm/download/ for unauthenticated users using a firewall or security plugin
  • If the plugin is not essential, consider disabling or permanently removing it to eliminate the attack surface

Generated by OpenCVE AI on August 3, 2026 at 22:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Shahjada
Shahjada wpdm Premium Packages
Wordpress
Wordpress wordpress
Vendors & Products Shahjada
Shahjada wpdm Premium Packages
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
Title WordPress WPDM – Premium Packages plugin <= 6.2.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Shahjada Wpdm Premium Packages
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T14:52:34.324Z

Reserved: 2026-07-13T06:13:34.178Z

Link: CVE-2026-61943

cve-icon Vulnrichment

Updated: 2026-07-23T14:10:34.514Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:33.930

Modified: 2026-07-23T15:17:39.163

Link: CVE-2026-61943

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:30:03Z

Weaknesses