Executive brief
WPDM – Premium Packages is a WordPress plugin used to manage and sell digital downloads. A security flaw in versions 6.2.0 and earlier allows unauthorized individuals to bypass access controls, potentially leading to the exposure of sensitive customer or product data. This could result in the unauthorized downloading of premium content or the disclosure of private information without any login credentials required.
Technical details
The WPDM – Premium Packages plugin for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862) in versions up to and including 6.2.0. This vulnerability allows an unauthenticated remote attacker to execute functions or access data that should be restricted to privileged users. The attack vector is network-based and requires no user interaction or prior authentication. Successful exploitation could lead to unauthorized data disclosure (Confidentiality: High). The issue is addressed in version 7.0.0.
Affected products
- Shahjada WPDM – Premium Packages <= 6.2.0
Timeline
- 2026-01-16: other: Reported by Nabil Irawan
- 2026-07-16: advisory: Patchstack advisory published
- 2026-07-23: disclosed: CVE published to NVD