Impact
The WPDM – Premium Packages plugin contains an unauthenticated broken access control flaw in versions up to and including 6.2.0. The vulnerability allows attackers to access functionality that is normally protected, because authentication checks are bypassed.
Affected Systems
The vulnerability affects the Shahjada WPDM – Premium Packages plugin for WordPress, versions up to and including 6.2.0. Any site running those versions is vulnerable; updating to 7.0.0 or later resolves the issue.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score of <1% reflects a very low current probability of exploitation, and the flaw is not listed in CISA's KEV catalog. The flaw can be reached remotely over the web without any prior authentication, so attackers can potentially exploit it via automated scans or targeted requests. No specific configuration or privileged state is required to launch an attack.
OpenCVE Enrichment