CVE-2026-19711
N/A
N/A
Summary
The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Premium Packages | 0 < 7.0.7 | affected |
Weaknesses
- CWE-284 Improper Access Control
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.