Executive brief
WPDM – Premium Packages is a WordPress plugin used to manage and sell digital downloads. A critical security flaw allows unauthorized individuals to execute database commands without logging in. This could lead to the theft of sensitive customer information, site data, or a partial disruption of service.
Technical details
An unauthenticated SQL injection vulnerability exists in the WPDM – Premium Packages plugin for WordPress (versions <= 6.2.0). The flaw is caused by improper neutralization of special elements used in an SQL command (CWE-89). A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the application, allowing them to interact directly with the underlying database. This can result in the extraction of sensitive data or unauthorized modification of database records. The vulnerability is addressed in version 7.0.0.
Affected products
- Shahjada WPDM – Premium Packages <= 6.2.0
Timeline
- 2026-04-29: other: Reported by HieuPenguinnn
- 2026-07-16: disclosed: Disclosed by Patchstack
- 2026-07-23: advisory: NVD published date
- 2026-07-23: patched: Patch confirmed available in version 7.0.0