Junglewise Threat Intelligence

CVE-2026-61948: Shahjada WPDM , Premium Packages unauthenticated SQL injection

CVE-2026-61948 · Severity: critical · CVSS 9.3 · Published 2026-07-23

Executive brief

WPDM – Premium Packages is a WordPress plugin used to manage and sell digital downloads. A critical security flaw allows unauthorized individuals to execute database commands without logging in. This could lead to the theft of sensitive customer information, site data, or a partial disruption of service.

Technical details

An unauthenticated SQL injection vulnerability exists in the WPDM – Premium Packages plugin for WordPress (versions <= 6.2.0). The flaw is caused by improper neutralization of special elements used in an SQL command (CWE-89). A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the application, allowing them to interact directly with the underlying database. This can result in the extraction of sensitive data or unauthorized modification of database records. The vulnerability is addressed in version 7.0.0.

Affected products

  • Shahjada WPDM – Premium Packages <= 6.2.0

Timeline

  • 2026-04-29: other: Reported by HieuPenguinnn
  • 2026-07-16: disclosed: Disclosed by Patchstack
  • 2026-07-23: advisory: NVD published date
  • 2026-07-23: patched: Patch confirmed available in version 7.0.0

References

Related threats