CVE-2026-19711

The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-16 06:16

Updated : 2026-08-26 16:30


NVD link : CVE-2026-19711

Mitre link : CVE-2026-19711

CVE.ORG link : CVE-2026-19711


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control