SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-19711

MEDIUM · CVSS 6.5 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-16 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Premium Packages WordPress plugin prior to version 7.0.7 is vulnerable as it fails to validate withdrawal requests against the user's actual earned balance. This flaw allows any authenticated user, including those with no sales, to request arbitrary payout amounts, which can be approved by an administrator, potentially leading to unauthorized fund disbursements. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of financial exploitation.

CVE
CVE-2026-19711
Severity
MEDIUM
CVSS
6.5
EPSS
0.21%
WordPress

Original NVD Description

The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.