CVE-2026-19711: Unknown Premium Packages
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.
Affected products
- Unknown Premium Packages: before 7.0.7 (fixed in 7.0.7)
Published 2026-08-16. Last modified 2026-08-26.