WordPress Plugin Vulnerabilities
Premium Packages – Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount Withdrawal Request
Description
The plugin does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
ACCESS CONTROLS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Farid Narimanov
Submitter
Farid Narimanov
Submitter website
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-14 (about 2 days ago)
Added
2026-08-14 (about 1 day ago)
Last Updated
2026-08-14 (about 1 day ago)