Junglewise Threat Intelligence

CVE-2026-15906: codename065 Premium Packages SQL injection in orderby parameter

CVE-2026-15906 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Technologies: Codename065 Premium Packages – Sell Digital Products Securely. Vendors: Codename065.

Executive brief

The Premium Packages plugin for WordPress, which is used to manage and sell digital products, contains a security flaw that could allow an authorized user with administrative access to run unauthorized database commands. This could lead to the exposure of sensitive business information stored in the website's database. While the attack requires an existing account with high-level permissions, it represents a significant risk to data confidentiality.

Technical details

A generic SQL injection vulnerability exists in the Premium Packages – Sell Digital Products Securely plugin for WordPress due to insufficient escaping and lack of preparation on SQL queries involving the 'orderby' parameter. The flaw is located in multiple components including OrderService.php and list-order-renews.php. An authenticated attacker with administrator-level privileges can exploit this by appending malicious SQL queries to existing ones via a network request. This allows for the unauthorized extraction of sensitive data from the WordPress database. The issue is present in all versions up to and including 7.0.4.

Affected products

  • codename065 Premium Packages – Sell Digital Products Securely up to, and including, 7.0.4

Timeline

  • 2026-07-23: advisory: CVE-2026-15906 published by NVD/Wordfence

References

Related threats