CVE-2026-61948
Shahjada · WPDM – Premium Packages
The WPDM Premium Packages WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 6.2.0 and prior, permitting remote database query execution.
Executive summary
The WPDM Premium Packages plugin is susceptible to an unauthenticated SQL injection, creating a critical path for attackers to compromise database security.
Vulnerability
The plugin fails to properly neutralize special elements in SQL commands (CWE-89), enabling unauthenticated attackers to perform malicious database operations.
Business impact
Successful exploitation allows an attacker to bypass authentication and manipulate or extract data from the database. A CVSS score of 9.3 underscores the critical severity, which could result in significant data breaches or unauthorized access to sensitive digital assets managed by the plugin.
Remediation
Immediate Action: Update the WPDM – Premium Packages plugin to version 7.0.0 or higher.
Proactive Monitoring: Analyze application server logs for anomalous database interactions and monitor for unexpected administrative account activity.
Compensating Controls: Utilize a WAF to inspect incoming traffic for SQL injection payloads, which can provide an interim layer of protection if patching is delayed.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a significant security risk to the integrity of the WordPress site. Administrators must upgrade to version 7.0.0 immediately to remediate the flaw and prevent potential exploitation by malicious actors.