CyberRota Analysis
AI-GeneratedThe Premium Packages WordPress plugin prior to version 7.0.7 is vulnerable as it fails to validate withdrawal requests against the user's actual earned balance. This flaw allows any authenticated user, including those with no sales, to request arbitrary payout amounts, which can be approved by an administrator, potentially leading to unauthorized fund disbursements. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of financial exploitation.
Original NVD Description
The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.