Premium Packages – Sell Digital Products Securely < 7.0.7 - Authenticated (Subscriber+) Payment Bypass
Strategic Overview
- Status
- Patched in 7.0.7
- Affected Plugin
- Premium Packages – Sell Digital Products Securely
- Affected Version
< 7.0.7- CVSS
- 4.3Medium
- Weakness type
- CWE-602 · Client-Side Enforcement of Server-Side Security
- CVE
CVE-2026-19711
At a glance
CVE-2026-19711 is a medium-severity Client-Side Enforcement of Server-Side Security vulnerability in the Premium Packages WordPress plugin, affecting versions < 7.0.7. It carries a CVSS score of 4.3 (reachable over the network; low attack complexity). Exploitation requires an authenticated account at Subscriber level or above. The issue is fixed in version 7.0.7; sites on affected versions should update now. Disclosed August 2026, reported by Farid Narimanov.
Vulnerability Overview
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Payment Bypass in all versions up to 7.0.7 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass payments.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no interaction from a victim user.
CWE-602: Client-Side Enforcement of Server-Side Security
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
Remediation
Update to version 7.0.7, or a newer patched version
How does WordSec protect against this?
Because it turns on account access, WordSec's login security is the relevant layer: role-based two-factor, captcha and brute-force limits raise the cost of getting the account this needs. None of that substitutes for the fix: Premium Packages 7.0.7 closes this, and updating the plugin is the step that ends it.
- Login Security
- Alerts
External References
Related records
Other vulnerabilities in Premium Packages – Sell Digital Products Securely
- 8.8CVE-2023-4293: Premium Packages - Sell… Arbitrary User Meta Update
CVE-2023-4293 - 7.5CVE-2026-12800: Premium Packages <= 6.2.0 SQL Injection
CVE-2026-12800 - 7.5CVE-2026-61948: Premium Packages SQL Injection
CVE-2026-61948 - 7.2CVE-2026-73190: Premium Packages Stored XSS
CVE-2026-73190 - 6.5CVE-2026-15906: Premium Packages <= 7.0.4 SQL Injection
CVE-2026-15906 - 6.4CVE-2025-30991: Premium Packages <= 6.0.5 Stored Cross-Site Scripting
CVE-2025-30991 - 6.4CVE-2024-10164: Premium Packages - Sell Digital… Stored XSS
CVE-2024-10164 - 6.3CVE-2026-15348: Premium Packages Authentication Bypass to Non-Admin
CVE-2026-15348
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C