The WPDM Premium Packages WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 6.2.0 and prior, permitting remote data...
Description
The WPDM Premium Packages WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 6.2.0 and prior, permitting remote database query execution.
AI Analyst Comment
Remediation
Update Shahjada WPDM – Premium Packages to the latest version. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Shahjada
PRODUCT: WPDM – Premium Packages
AFFECTED_VERSIONS: up to and including 6.2.0
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The WPDM Premium Packages WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 6.2.0 and prior, permitting remote database query execution.
Executive Summary:
The WPDM Premium Packages plugin is susceptible to an unauthenticated SQL injection, creating a critical path for attackers to compromise database security.
Vulnerability Details
CVE-ID: CVE-2026-61948
Affected Software: Shahjada WPDM – Premium Packages
Affected Versions: up to and including 6.2.0
Vulnerability: The plugin fails to properly neutralize special elements in SQL commands (CWE-89), enabling unauthenticated attackers to perform malicious database operations.
Business Impact
Successful exploitation allows an attacker to bypass authentication and manipulate or extract data from the database. A CVSS score of 9.3 underscores the critical severity, which could result in significant data breaches or unauthorized access to sensitive digital assets managed by the plugin.
Remediation Plan
Immediate Action: Update the WPDM – Premium Packages plugin to version 7.0.0 or higher.
Proactive Monitoring: Analyze application server logs for anomalous database interactions and monitor for unexpected administrative account activity.
Compensating Controls: Utilize a WAF to inspect incoming traffic for SQL injection payloads, which can provide an interim layer of protection if patching is delayed.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 23, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability is highly automatable due to the lack of required authentication.
Analyst Recommendation
This vulnerability represents a significant security risk to the integrity of the WordPress site. Administrators must upgrade to version 7.0.0 immediately to remediate the flaw and prevent potential exploitation by malicious actors.